The public sector, answered in full.
- questions in this group, each answered in full
- 18
- pages the answers are written on, every one linked
- 1
- questions across the whole FAQ
- 1424
18 questions on the public sector, answered by Tenhaw, a UK AI consultancy and AI delivery partner based in London. Nothing here is a summary: each answer is the exact text from the page that owns it, and every group links back to that page for the context around it.
Elsewhere in the FAQ
Public Sector and Government
Answered on Public Sector and Government, and rendered here in the same words.
Read the page these answers live on →
Does Tenhaw work with the public sector?
Yes. Tenhaw was Tecknuovo's portfolio manager, hands on under the contract, and in that role built a centralised portfolio management office from nothing over nine months and ran it live across 19 projects, including public sector delivery for HMRC, the MOD and Thames Water, while coaching the junior delivery leads who took it over. Tecknuovo's own teams delivered those projects; the office is what made them visible, comparable and manageable, and it reinforced their credibility on exactly that work. Alongside it sits the agentic evidence, a two-week London specialty insurance proof of concept taking PDFs to business intelligence on Azure, now being productionised in month three.
What does the Algorithmic Transparency Recording Standard require of an AI supplier?
Strictly, nothing. The standard binds the organisation, not the supplier, though in practice it decides what a supplier has to produce. The standard is mandatory for central government departments and for arm's length bodies that deliver public services or engage directly with the public, and it asks for a published record of what the algorithmic tool is, why the organisation is using it, how it works, the data behind it and the human oversight around it. That means the facts have to exist inside delivery: purpose, data sources, models and versions, human oversight points and named owners, all current rather than as at launch. The test is simple. Ask whether their build produces those fields as outputs, and what happens to the published record when a prompt or a retrieval corpus changes next month.
Can a government department let an AI agent decide a case?
It depends on whether the decision is significant and whether a human is meaningfully involved. Section 80 of the Data (Use and Access) Act 2025 replaced Article 22 of the UK GDPR with Articles 22A to 22D. A significant decision is one with a legal effect or a similarly significant effect on the person, and whether it counts as solely automated turns on meaningful human involvement, judged including by how far the decision is reached through profiling. Where there is no meaningful human involvement, safeguards are required: information about the decision, the ability to make representations, human intervention by the controller and the ability to contest the outcome. Special category data narrows it further, needing explicit consent or a specific legal footing. The design consequence is that a caseworker with a recommendation, a score and a handling time target is probably not meaningful involvement, so the reviewer has to see the evidence, be able to disagree, and have that disagreement recorded. Tenhaw is not your DPO and this is not legal advice.
How is agentic AI bought in UK government?
Through the same routes as other digital work, and the route shapes the engagement. G-Cloud 14 (RM1557.14) is a catalogue for cloud hosting, cloud software and cloud support. Digital Outcomes and Specialists 7 (RM1043.9) went live on 30 January 2026 as an open framework under the Procurement Act 2023, with four lots covering digital outcomes, capability and delivery partners, specialists, and user research, and it requires a further competition rather than a direct award. Both are run by the Government Commercial Agency, which Crown Commercial Service became on 1 April 2026. Over the top sits the Digital, Data and Technology Playbook, which asks for outcome-based specifications and a delivery model assessment on a comply or explain basis. The practical advice is to settle the route before the design, because an outcomes lot and a specialists lot produce different teams, different pricing and different evidence.
Did Cabinet Office spend controls end, and what replaced them for AI projects?
Most Cabinet Office spend controls ceased as a requirement on 1 April 2026, with the advertising, marketing and communications control the exception. Digital and technology assurance did not end with them. It moved to the Digital Assurance Playbook, published by the Department for Science, Innovation and Technology on the same date. Under it, organisations design their own assurance across three levels: operational, senior management and independent review. They still share a forward pipeline of digital and technology spend above £5 million whole life cost, with a £0 threshold for cryptographic products. For AI specifically, assurers are asked to check that the initiative follows the AI Playbook for the UK Government. So the gate is now inside your organisation rather than in the centre, it is not identical between departments, and a delivery plan that has not mapped it is planning against a process that no longer exists.
What should a department ask an agentic AI supplier to evidence?
Five things, all of which should exist before a contract is signed. Which decisions the agent may take and which need a human, written down as an inventory rather than described in a workshop. Where the human sits, what they see, and how their disagreement is recorded, because meaningful human involvement is a design property and not a claim. How the transparency record will be produced and kept true when prompts, corpora and model versions change. What the system emits as evidence while it runs, rather than what can be reconstructed from logs afterwards. And who owns the prompts, evaluation sets and retrieval corpora on exit. Ask every supplier, us included, to show those five as artefacts from delivered work.
Has Tenhaw delivered an AI system inside a government department?
Our government record is portfolio delivery. Tenhaw was Tecknuovo's portfolio manager, hands on under the contract, standing up a portfolio management office from nothing and running it live across 19 projects, including delivery for HMRC, the MOD and Thames Water, where the governance record had to stay current as the work ran rather than be assembled afterwards. The agentic builds so far sit in other sectors. A two-week London specialty insurance proof of concept took PDFs to business intelligence on Azure, pair-programmed with the client's own engineer and now being productionised in month three, and more than twenty agentic products have come through Velocity84, Tenhaw's build lab.
Is the AI Playbook for the UK Government mandatory?
In practice yes, even though it reads as guidance rather than law. The Government Digital Service published the Playbook on 10 February 2025, updating the Generative AI Framework for HMG, with ten principles for civil servants building or buying AI. Since assurance moved inside departments on 1 April 2026, the Digital Assurance Playbook asks assurers to check that initiatives using AI follow it, so your gate reviewer applies it. Four principles decide a build: knowing what AI is and what its limitations are, using it lawfully, ethically and responsibly, meaningful human control at the right stages, and working with commercial colleagues from the start. We treat those as acceptance criteria, not lines to cite in a bid.
What can a department automate before touching casework decisions?
Plenty, and the order matters more than the ambition. The workflows worth taking first are internal: knowledge retrieval across policy, guidance and procedure you already publish, casework preparation and triage with the decision itself left with the caseworker, drafting and correspondence with a named human accountable for what goes out, portfolio and delivery reporting across a programme, assurance and audit evidence gathering where the record is the product, and developer workflow inside your own teams, where the risk surface is contained. None of those decides a citizen's outcome. We sequence citizen-facing decisioning last because the evidence base you will need to defend it is far cheaper to build where nobody is affected while you are learning.
Can a department extend an AI proof of concept into a production contract?
Treat production as a separate procurement, not an extension. A proof of concept that works produces an immediate request to productionise it, usually a different requirement at a different value, which is how agentic programmes creep by default. Under the Procurement Act 2023 what was bought, why, and what changed get published. Handled late it is a contract change notice nobody planned for; handled at the start it is simply the next procurement. We scope the proof of concept as a fixed-price outcome with its own end point, £20k–£55k over two to four weeks, and say up front that productionising is a separate decision with its own route. What may be awarded, and how, is your commercial function's call.
What actually slows down public sector AI transformation in the UK?
Not the technology. Public sector AI transformation in the UK is gated by three published duties that already exist: what an organisation has to record in public about an algorithmic tool, what may be decided about a citizen without meaningful human involvement, and how the work is bought. The AI Playbook for the UK Government sits over the top, and since 1 April 2026 digital and technology assurance runs inside your own organisation rather than through a central Cabinet Office control. Programmes stall when none of that is settled before the build is scoped, and the approval path is not the same in any two departments. Settle it first and the build is the straightforward part.
What happens when the NAO or a select committee asks about our AI system?
They read the published record before anyone talks to you. Contracts are published under the Procurement Act 2023 and transparency records are public, and select committees, the National Audit Office and journalists read both, so evidence of governance is part of the deliverable rather than an internal comfort. The practical test is whether the system produces that evidence while it runs: purpose, data sources, models, human oversight points and named owners, current rather than as at launch. That is what we found running a portfolio office over public sector delivery at Tecknuovo, where the record had to exist as the work ran rather than be assembled afterwards from a sales deck.
Do we need a delivery model assessment for an agentic AI project?
For a central government department or arm's length body, yes, on a comply or explain basis. The Digital, Data and Technology Playbook carries eleven policies, four of which shape an agentic programme: a commercial pipeline published well ahead of the work, a delivery model assessment with a should cost model behind it, specifications that are outcome-based rather than prescriptive, and testing and learning where a service is delivered in a new way. The awkward part is costing a delivery model before anyone knows what the agents will do, which is why both of our entry rungs are fixed price and time-boxed, £44,000 over four weeks for the audit and £20k–£55k over two to four weeks for a proof of concept.
When should commercial and legal join a government AI project?
Before the technical design, not after it. Working with commercial colleagues from the start is one of the AI Playbook's ten principles, and the usual failure is commercial arriving late, by which point the design has already decided what the contract has to say about model changes, data and exit. Your data protection officer and legal advisers come in at the same point on anything touching a citizen. We would rather have them in the design session than in the approval queue. Add whoever approves at each of your three assurance levels, operational, senior management and independent review, because the approval path is departmental now and differs between organisations.
What if a citizen challenges a decision our agent helped make?
You have to be able to say what drove the output on the day, months after the day. Articles 22A to 22D give the person information about the decision, the ability to make representations, human intervention by the controller and the ability to contest the outcome. The failure we design against is a contest route that exists on paper and cannot answer the citizen's question, because nothing kept a record of what drove the output and the retrieval corpus has moved on. So the reasons trail is retained inside the workflow rather than in logs on thirty day retention, and a reviewer's disagreement is recorded as an outcome. Whether a decision is significant is a call for your DPO.
Will an AI readiness audit produce evidence our assurance gate accepts?
That is what it is designed for. Since 1 April 2026 organisations design their own assurance across three levels, operational, senior management and independent review, and assurers are asked to check that AI initiatives follow the AI Playbook. The audit is £44,000 fixed over four weeks and ends in working prototypes. Its other outputs are a decision inventory holding purpose, data sources, models, human oversight points and named owners, an agreed autonomy boundary, and an evidence trail the system emits as it runs. Those map closely to what each level of assurance asks for, deliberately. We do not sit in your approval chain, so we ask who approves at each stage before agreeing a plan.
Do your people hold security clearance for government work?
Everyone with client access is BS7858 screened before they touch anything, Cyber Essentials Plus is in progress and ISO 27001 is targeted for 2027, all published on the security page. Vetted SC or DV clearance is not on that list, so settle that before scoping rather than during delivery. Where the work does not need it, we deploy on your infrastructure under your policies as usual, with UK data residency by default and the EU available, and the team is two or three senior people with James Rooney leading the engagement personally.
Do the UK government AI rules apply to councils too?
It splits, so check before anyone quotes a duty at you. The Algorithmic Transparency Recording Standard is mandatory for central government departments and for arm's length bodies that deliver public services or engage directly with the public, recommended for the wider public sector, with a scope and exemptions policy published in December 2024. The Digital, Data and Technology Playbook binds central departments and their arm's length bodies on a comply or explain basis, with the wider public sector expected to take it into account. Two duties do not split. Articles 22A to 22D reach any controller taking significant decisions about people, and the Procurement Act 2023 applies to contracting authorities across the public sector.
If the sources do not answer it, a call will.
Talk it through1424 questions, grouped by subject
Every question answered anywhere on tenhaw.com sits in one of 51 groups. This is one of them.
- Whether sector experience matters15
- Financial services regulation7
- Agents in banking and insurance11
- Retail, industry and energy36
All 1424questions, and every group →
Or ask the question directly and skip the categories.
Talk it throughStill have a question?
A 30-minute discovery call with James Rooney. Bring the question this page did not answer. You'll leave with a rough scope whether you engage us or not.
most start with a fixed-price AI Readiness Audit · £44,000 · 4 weeks · working prototypes
Calendar not loading? Open it on cal.com or email hello@tenhaw.com.