Agentic transformation, by sector.

The constraints differ more than the technology does. What gates a programme in each sector, where agents create value first, what we have delivered there, and the sectors we would not take on yet.

sectors, each with named work behind it
4
organisations behind the work, as clients or as roles held
11
engagements written up across them
8
Why these

A sector page with no work behind it is a keyword page

Most consultancies list twelve sectors and can evidence two. These are the ones where we can point at named engagements, say what each one was, and tell you which parts of it transfer to you.

01

Financial Services

  • London specialty insurance market12 months → 2 weeks prior build effort rebuilt as a working proof of concept. Live now, unnamed at the client's request.
  • HSBC500 teams in scope
  • HSBC1.5M+ hours/year of admin removed (projected)
Banking
SM&CR, SS1/23 model risk, Consumer Duty, operational resilience
Insurance
Solvency II and Solvency UK, Lloyd's delegated authority and binding authorities, the actuarial function
02

Retail, Consumer and Media

  • Discovery6 development teams coordinated
  • Greggs2 squads: Mobile App and Integration
03

Industrial, Energy and Infrastructure

  • Anglo American£40bn business case underpinned
  • Yondr3 regions: UK, USA, Singapore
04

Public Sector and Government

  • Tecknuovo19 projects overseen
Departments and ALBs
the Algorithmic Transparency Recording Standard, the AI Playbook, automated decisions under the Data (Use and Access) Act
Suppliers to government
the Digital, Data and Technology Playbook, G-Cloud 14 and Digital Outcomes and Specialists 7, the Procurement Act 2023

One of our engagements is running right now and is confidential at the client's request, so it is written up unnamed. Every engagement, written up in full.

The short answer

What agentic transformation looks like in each

The opening paragraph of each sector page, so you can tell in one screen which of the four is yours.

Financial Services

Agentic transformation in UK financial services fails on governance far more often than on technology. The FCA and the PRA have written no separate AI rulebook and have said they do not intend to, so the obligations you already answer to apply to agents in full. They decide which workflows can move to agents at all, and in what order.

Tenhaw designs agentic operating models where the audit trail and the human-in-the-loop points are part of the design rather than a retrofit after an incident. Tenhaw is an AI delivery partner, not a compliance consultancy: the method produces the evidence your second line needs, it does not replace them.

Where agents land first: operational process with high volume and cheaply reversible decisions. The 7regimes that gate it →

Retail, Consumer and Media

Retail, consumer and media organisations see the fastest agentic returns because volume is high, feedback loops are short and decisions are frequently reversible, but they also have the least tolerance for a transformation that takes eighteen months to show results. The regulatory floor is lower than in financial services, and it is not absent. Since 6 April 2025 the CMA has enforced consumer protection law directly under the DMCC Act, which puts anything an agent writes for a customer squarely inside the unfair commercial practices rules, and UK GDPR governs the personalisation data underneath it. Tenhaw has run delivery transformation at Greggs, Sky, Discovery+, YOOX NET-A-PORTER and Colart, and sequences agentic programmes so something is in production inside a peak-trading cycle rather than after it.

Where agents land first: merchandising and demand signals, where decisions are frequent and reversible. The 3regimes that gate it →

Industrial, Energy and Infrastructure

Industrial, energy and infrastructure organisations face the inverse of the retail problem: decisions are consequential and expensive to reverse, assets have decade-long lifecycles, and teams are distributed across continents and time zones. The binding constraints here are safety cases and OT security rather than conduct regulation. That means management of change under a functional safety regime, and the boundary between corporate IT and the control domain that the NIS Regulations, NIS2 and IEC 62443 exist to protect. Agentic value concentrates in engineering knowledge work, simulation and planning, not in operational decisioning. Tenhaw built and ran the digital teams behind Anglo American's £40bn hydrogen business case and made global delivery predictable at Yondr across the UK, US and Singapore.

Where agents land first: engineering knowledge retrieval across decades of technical documentation. The 3regimes that gate it →

Public Sector and Government

Agentic delivery in UK government is not gated by a new AI rulebook. It is gated by three published duties that already exist: what an organisation has to record in public about an algorithmic tool, what may be decided about a citizen without meaningful human involvement, and how the work is bought. The AI Playbook for the UK Government sits over the top of those, and departments now run their own digital assurance rather than passing through a central Cabinet Office control.

Tenhaw has not delivered an agentic system inside a government department. What we hold is delivery-transformation exposure to public sector programmes through a supplier, not agentic delivery to a department: at Tecknuovo we built a centralised portfolio office from nothing and ran it across 19 projects, including engagements delivering to HMRC, the MOD and Thames Water. If you need a supplier who has already taken an agentic system through a department's assurance, say so on the call and we will tell you that we are not it yet.

Where agents land first: internal knowledge retrieval across policy, guidance and procedure that is already published. The 6regimes that gate it →

Where we would say no

Sectors we would not take on yet

Four sectors with pages, and a list of the ones without. We have no engagement in any of these, and in each case there is a specific capability we would need before we could take the work rather than a gap we could close during it.

Healthcare and life sciences

Tenhaw has no healthcare or life sciences engagement, and we would not take an agentic build in a clinical setting today. The gap is not domain knowledge, which is hireable. It is a standing clinical safety capability, which is not.

What gates it
Software with a medical purpose is regulated as a medical device in Great Britain under the UK MDR 2002, which the MHRA enforces, and an AI product has to conform before it is placed on the market. Health IT delivered into the NHS also sits under two clinical risk management standards: DCB0129, published under section 250 of the Health and Social Care Act 2012, which binds the manufacturer of a health IT system, and DCB0160, which covers the organisation deploying and using it. Products sold into the NHS are assessed against the Digital Technology Assessment Criteria, covering clinical safety, data protection, technical security, interoperability, and usability and accessibility, and that assessment applies alongside other required approvals rather than replacing them.
What would have to be true first
A named clinical safety officer inside the delivery team, and a clinical risk management system producing a hazard log and a clinical safety case report as the work runs rather than assembled at the end. Where the intended use makes the software a medical device, a conformity route and a quality management system behind it. Those are standing capabilities, not things a firm buys in for one engagement, and a supplier who offers to acquire them during your programme is asking you to fund their learning.
Who to look for instead
A supplier who can name their clinical safety officer, show you a hazard log and a clinical safety case report from a system already in use, and, for a medical device, evidence their conformity route. Ask for those three before anyone opens a slide about models.

Legal and professional services

We have no legal sector engagement, and we would not build an agentic system over live matter files. We would look at a law firm's back office on the same terms as any other business, and we would say no to anything touching client work.

What gates it
Solicitors work to the SRA Code of Conduct. Paragraph 6.3 requires that the affairs of current and former clients are kept confidential unless disclosure is required or permitted by law or the client consents. Paragraph 6.4 sets out the narrow exceptions to telling a client what you know, including where the information sits in a privileged document you have seen only because it was disclosed by mistake. Paragraphs 3.5 and 3.6 keep the supervisor accountable for work done through others and for their competence. Legal professional privilege sits over all of it, and the Code treats privileged material as a category of its own.
What would have to be true first
Certainty that privileged material cannot leave the firm's control through a model, a retrieval corpus, a log or a subprocessor, and that the information barriers between matters hold inside the system as strictly as they hold inside the practice. Then a supervising solicitor able to account for what the system produced, which is a different bar from a reviewer signing off an output. We would want those answered before a build rather than during one, and we would expect the firm's insurer to have a view.
Who to look for instead
A legal technology supplier that already operates inside firms' information barrier arrangements, can say exactly where matter data is processed and by whom, and whose contract deals with privilege directly rather than by reference to a general confidentiality clause. Your risk and compliance partner and your professional indemnity insurer will reach a view on that faster than your IT function will.

Telecommunications

No telco engagement, and the network itself is a specialist security discipline we do not hold. We would take business-side work in a telecommunications company, corporate functions, delivery and knowledge work, on exactly the terms we would take it in any other large organisation. We would not go near the network.

What gates it
Providers of public electronic communications networks and services carry security duties under the Telecommunications (Security) Act 2021, which amended the Communications Act 2003: a duty to take security measures, a duty to act on security compromises, and duties to inform users and others. Ofcom enforces them, publishes its general policy on doing so under section 105Y of the Communications Act 2003, and works alongside the NCSC and the ICO. The detail providers actually work to sits in the Electronic Communications (Security Measures) Regulations 2022 and the Telecommunications Security Code of Practice.
What would have to be true first
Engineers with real network security experience working to the code of practice the provider is held to, and a clear line showing where an agent may read and whether it may write anything at all. That is the same argument we make about the boundary into an industrial control domain, and in telecoms we would be the wrong people to be making it.
Who to look for instead
For anything network-adjacent, a supplier already working to the same code of practice you are, who can be named in your compliance evidence. For the business side of the same organisation, judge us as you would in any large enterprise, and read the industrial and energy page, where the same identity and boundary questions are the ones we do answer.

This list is a current position, not a permanent one. If we hire or partner into one of these and can point at the work, it gets a page with named evidence on it like the other four. Every engagement we have, in full.

Work in one of these sectors?

Thirty minutes with James Rooney. You will leave with a rough scope and a view on where agents would pay back first in your organisation.

30 minutesWith James personallyNo obligation

Most organisations start with a fixed-price Agent-Readiness Audit · £30k–£90k · 6–8 weeks