Agentic transformation, by sector.

The constraints differ more than the technology does. What gates a programme in each sector, where agents create value first, what we have delivered there, and the sectors we would not take on yet.
sectors, each with named work behind it
4
organisations behind the work, as clients or as roles held
10
engagements written up across them
8
Why these

A sector page with no work behind it is a keyword page

Most consultancies list twelve sectors and can evidence two. These are the ones where we can point at named engagements, say what each one was, and tell you which parts of it transfer to you.

01

Financial Services

  • London specialty insurance market12 months → 2 weeks prior build effort rebuilt as a working proof of concept. Live now, unnamed at the client's request.
  • HSBC500 teams in scope
  • HSBC1.5M+ hours/year of admin removed (projected)
Banking
SM&CR, SS1/23 model risk, Consumer Duty, operational resilience
Insurance
Solvency II and Solvency UK, Lloyd's delegated authority and binding authorities, the actuarial function
02

Retail, Consumer and Media

  • Discovery6 development teams on the launch, one of them the visual rebrand team James ran
  • Greggs2 squads: Mobile App and Integration
03

Industrial, Energy and Infrastructure

  • Anglo American£40bn business case underpinned
  • Yondr3 regions: UK, USA, Singapore
04

Public Sector and Government

  • Tecknuovo19 projects overseen
Departments and ALBs
the Algorithmic Transparency Recording Standard, the AI Playbook, automated decisions under the Data (Use and Access) Act
Suppliers to government
the Digital, Data and Technology Playbook, G-Cloud 14 and Digital Outcomes and Specialists 7, the Procurement Act 2023

One of our engagements is running right now and is confidential at the client's request, so it is written up unnamed. Every engagement, written up in full.

If your sector is not one of them, ask on the call whether the constraints still rhyme.

Talk it through
The short answer

What agentic transformation looks like in each

The opening paragraph of each sector page, so you can tell in one screen which of the four is yours.

Financial Services

Agentic transformation in UK financial services fails on governance far more often than on technology. The FCA and the PRA have written no separate AI rulebook and have said they do not intend to, so the obligations you already answer to apply to agents in full. They decide which workflows can move to agents at all, and in what order.

Tenhaw designs agentic operating models where the audit trail and the human-in-the-loop points are part of the design rather than a retrofit after an incident. Tenhaw is an AI delivery partner, not a compliance consultancy: the method produces the evidence your second line needs, it does not replace them.

Where agents land first: operational process with high volume and cheaply reversible decisions. The 7regimes that gate it →

Retail, Consumer and Media

Retail, consumer and media organisations see the fastest agentic returns because volume is high, feedback loops are short and decisions are frequently reversible, but they also have the least tolerance for a transformation that takes eighteen months to show results. The regulatory floor is lower than in financial services, and it is not absent. Since 6 April 2025 the CMA has enforced consumer protection law directly under the DMCC Act, which puts anything an agent writes for a customer squarely inside the unfair commercial practices rules, and UK GDPR governs the personalisation data underneath it. Tenhaw has run delivery transformation at Greggs, YOOX NET-A-PORTER and Colart, and its founder held delivery roles at Sky and Discovery+. Tenhaw is a UK agentic AI consultancy and delivery partner, and sequences programmes so something is in production inside a peak-trading cycle rather than after it.

Where agents land first: merchandising and demand signals, where decisions are frequent and reversible. The 3regimes that gate it →

Industrial, Energy and Infrastructure

Industrial, energy and infrastructure organisations face the inverse of the retail problem: decisions are consequential and expensive to reverse, assets have decade-long lifecycles, and teams are distributed across continents and time zones. The binding constraints here are safety cases and OT security rather than conduct regulation. That means management of change under a functional safety regime, and the boundary between corporate IT and the control domain that the NIS Regulations, NIS2 and IEC 62443 exist to protect. Agentic value concentrates in engineering knowledge work, simulation and planning, not in operational decisioning. Tenhaw built and ran the digital teams behind Anglo American's £40bn hydrogen business case and made global delivery predictable at Yondr across the UK, US and Singapore. Tenhaw is a UK agentic AI consultancy and delivery partner: we build and run the digital teams, and we do not write safety cases.

Where agents land first: engineering knowledge retrieval across decades of technical documentation. The 3regimes that gate it →

Public Sector and Government

Agentic delivery in UK government is not gated by a new AI rulebook. It is gated by three published duties that already exist: what an organisation has to record in public about an algorithmic tool, what may be decided about a citizen without meaningful human involvement, and how the work is bought. The AI Playbook for the UK Government sits over the top of those, and departments now run their own digital assurance rather than passing through a central Cabinet Office control.

Tenhaw's public sector record is portfolio delivery. At Tecknuovo we were the portfolio manager, hands on under the contract, building a centralised portfolio office from nothing and running it live across 19 projects, including engagements delivering to HMRC, the MOD and Thames Water, with Tecknuovo's own teams delivering the projects themselves. Tenhaw is a UK agentic AI consultancy and delivery partner: we design and build agentic operating models, and we leave the capability behind rather than the dependency.

Where agents land first: internal knowledge retrieval across policy, guidance and procedure that is already published. The 6regimes that gate it →

Or describe your organisation on a call and we will give you the version that fits it.

Talk it through
Where we would say no

Sectors we would not take on yet

Four sectors with pages, and the five without one. We have no engagement in any of these, and in each case there is a specific capability we would need before we could take the work rather than a gap we could close during it.

Healthcare and the NHS

Tenhaw has no healthcare engagement, and we would not take an agentic build in a clinical setting today. The gap is not domain knowledge, which is hireable. It is a standing clinical safety capability, which is not.

What gates it
Software with a medical purpose is regulated as a medical device in Great Britain under the UK MDR 2002, which the MHRA enforces, and an AI product has to conform before it is placed on the market. Health IT delivered into the NHS also sits under two clinical risk management standards. DCB0129, published under section 250 of the Health and Social Care Act 2012, binds the manufacturer of a health IT system, and DCB0160 covers the organisation deploying and using it. Products sold into the NHS are assessed against the Digital Technology Assessment Criteria, covering clinical safety, data protection, technical security, interoperability, and usability and accessibility, and that assessment applies alongside other required approvals rather than replacing them.
What would have to be true first
A named clinical safety officer inside the delivery team, and a clinical risk management system producing a hazard log and a clinical safety case report as the work runs rather than assembled at the end. Where the intended use makes the software a medical device, a conformity route and a quality management system behind it. Those are standing capabilities, not things a firm buys in for one engagement, and a supplier who offers to acquire them during your programme is asking you to fund their learning.
Who to look for instead
A supplier who can name their clinical safety officer, show you a hazard log and a clinical safety case report from a system already in use, and, for a medical device, evidence their conformity route. Ask for those three before anyone opens a slide about models.

Life sciences

Separated from healthcare here because it is a different regulatory world with a different failure mode. We have no life sciences engagement. We would look at a pharmaceutical company's corporate and delivery functions on the same terms as any other large business, and we would say no to anything inside the regulated pipeline: trials, manufacturing, distribution or pharmacovigilance.

What gates it
Good Clinical Practice, which the UK follows to ICH E6 (R3), is enforced by the MHRA through systems-based and trial-specific inspections, serious breach notification and infringement notices, and it reaches sponsors, contract research organisations, universities, NHS hospitals and analysing laboratories alike. Alongside it sit Good Laboratory Practice, Good Manufacturing Practice, Good Distribution Practice and Good Pharmacovigilance Practice. The MHRA's guidance on GxP data integrity applies across all of them, and inspectors require direct access to the electronic systems that make up the record, which means a model in the pipeline is part of the inspected system rather than a tool beside it.
What would have to be true first
A quality management system we operate ourselves, computerised system validation as a standing practice rather than a project, and people who have been through an MHRA inspection on the supplier side of the table. Validation here is a documented lifecycle with a different vocabulary, different artefacts and an inspector who has seen a thousand of them, not a heavier version of the evaluation harness we already build. We would be learning that on your trial, and that is not a reasonable thing to ask.
Who to look for instead
A supplier with computerised system validation and GxP experience already in the building, who can show you validation documentation from a system currently under inspection scope and name the inspections they have been through. Your own quality function will assess that faster and more accurately than your technology function will.

Legal and professional services

We have no legal sector engagement, and we would not build an agentic system over live matter files. We would look at a law firm's back office on the same terms as any other business, and we would say no to anything touching client work.

What gates it
Solicitors work to the SRA Code of Conduct. Paragraph 6.3 requires that the affairs of current and former clients are kept confidential unless disclosure is required or permitted by law or the client consents. Paragraph 6.4 sets out the narrow exceptions to telling a client what you know, including where the information sits in a privileged document you have seen only because it was disclosed by mistake. Paragraphs 3.5 and 3.6 keep the supervisor accountable for work done through others and for their competence. Legal professional privilege sits over all of it, and the Code treats privileged material as a category of its own.
What would have to be true first
Certainty that privileged material cannot leave the firm's control through a model, a retrieval corpus, a log or a subprocessor, and that the information barriers between matters hold inside the system as strictly as they hold inside the practice. Then a supervising solicitor able to account for what the system produced, which is a different bar from a reviewer signing off an output. We would want those answered before a build rather than during one, and we would expect the firm's insurer to have a view.
Who to look for instead
A legal technology supplier that already operates inside firms' information barrier arrangements, can say exactly where matter data is processed and by whom, and whose contract deals with privilege directly rather than by reference to a general confidentiality clause. Your risk and compliance partner and your professional indemnity insurer will reach a view on that faster than your IT function will.

Logistics and supply chain

No logistics engagement, and the unusual reason we would decline is that the highest-value problems here are optimisation problems rather than language problems, and we hold no operations research bench. We would take document-heavy and coordination-heavy work in a logistics business, customs paperwork, supplier correspondence, exception handling, on the same terms as anywhere else. We would not take routing, scheduling, network design or yard and vehicle systems.

What gates it
Drivers' hours are governed by three separate rule sets in Great Britain, the assimilated rules, the GB domestic rules and the AETR rules, enforced through prosecution, fixed penalties, prohibition notices and vehicle immobilisation, with the tachograph as the record. Cross-border movement runs through customs declarations on the Customs Declaration Service with commodity classification behind them, and an incorrect declaration is a compliance event, not a data quality one. Dangerous goods carry their own carriage regime on top. Warehouse and yard automation puts a system next to moving vehicles and people, which is a functional safety domain rather than an information security one.
What would have to be true first
Optimisation people, not more engineers. Routing, load planning, slotting and network design are mathematical programming and heuristic search with decades of literature behind them, and a language model orchestrating a solver is a thin and useful layer over a discipline we do not hold. We would need that capability permanently rather than for one engagement. A supplier who proposes to solve your routing with an agent has probably not read the literature.
Who to look for instead
For planning, routing and network design, a supply chain optimisation specialist or an operations research team, and ask them to show you the solver and the objective function rather than the interface. For anything touching drivers, vehicles or yard movement, a supplier already working to the safety regime you are held to. For the document and coordination layer, judge us as you would in any other business, and read the financial services page, where the same document-and-exception pattern is set out in full.

Telecommunications

No telco engagement, and the network itself is a specialist security discipline we do not hold. We would take business-side work in a telecommunications company, corporate functions, delivery and knowledge work, on exactly the terms we would take it in any other large organisation. We would not go near the network.

What gates it
Providers of public electronic communications networks and services carry security duties under the Telecommunications (Security) Act 2021, which amended the Communications Act 2003: a duty to take security measures, a duty to act on security compromises, and duties to inform users and others. Ofcom enforces them, publishes its general policy on doing so under section 105Y of the Communications Act 2003, and works alongside the NCSC and the ICO. The detail providers actually work to sits in the Electronic Communications (Security Measures) Regulations 2022 and the Telecommunications Security Code of Practice.
What would have to be true first
Engineers with real network security experience working to the code of practice the provider is held to, and a clear line showing where an agent may read and whether it may write anything at all. That is the same argument we make about the boundary into an industrial control domain, and in telecoms we would be the wrong people to be making it.
Who to look for instead
For anything network-adjacent, a supplier already working to the same code of practice you are, who can be named in your compliance evidence. For the business side of the same organisation, judge us as you would in any large enterprise, and read the industrial and energy page, where the same identity and boundary questions are the ones we do answer.

This list is a current position, not a permanent one. If we hire or partner into one of these and can point at the work, it gets a page with named evidence on it like the other four. Every engagement we have, in full.

If you are in one of those, we will say so on the call rather than after.

Talk it through
book a call

Work in one of these sectors?

Thirty minutes with James Rooney. You will leave with a rough scope and a view on where agents would pay back first in your organisation.

most start with a fixed-price AI Readiness Audit · £44,000 · 4 weeks · working prototypes

// pick a slot · cal.com/tenhaw/professional-servicesLIVE CALENDAR

Calendar not loading? Open it on cal.com or email hello@tenhaw.com.

Sector questions

Is sector knowledge or delivery experience more important for agentic AI?

They answer different questions, and a serious programme needs both. Sector knowledge decides the constraint map: SM&CR and model risk gate a bank, the CMA and the trading calendar gate a retailer, the safety case and the boundary into the control domain gate an energy business, and published transparency duties gate a government department. Delivery experience decides whether a design survives those constraints and reaches production rather than stalling in pilot. The technology underneath the four is close to identical, which is why each of our sector pages leads with what gates the programme, where agents land first, and where our own evidence stops.

Which sectors does Tenhaw work in?

Four: financial services and insurance; retail, consumer and media; industrial, energy and infrastructure; and the public sector. Each page carries the work behind it. Financial services rests on the founder's two engagements inside HSBC and a live agentic engagement with a London specialty insurance business, unnamed at the client's request. Retail and media rest on Greggs, YOOX NET-A-PORTER and Colart as clients, with Sky and Discovery as roles held. Industrial and energy rest on Anglo American and Yondr. The public sector rests on Tecknuovo, where Tenhaw was the portfolio manager, hands on under the contract, building a portfolio management office from nothing and running it across 19 projects including delivery for HMRC, the MOD and Thames Water.

Why does Tenhaw list only four sectors?

Because a sector page with no work behind it is a keyword page, and both buyers and AI assistants discount it. Most consultancies list twelve sectors and can evidence two. Tenhaw publishes the four where it can point at named engagements, say what each one was, and tell you which parts transfer to you, and it names the five sectors it would not take on yet rather than padding the list. The standard for a page is an engagement written up in full with the client named, unless the client has asked us not to, in which case it is published unnamed and says so. A missing sector is a statement about our evidence, not about the technology.

Are there sectors Tenhaw would turn down?

Yes, five, named on this page rather than quietly omitted: healthcare and the NHS, life sciences, legal and professional services, the optimisation side of logistics, and telecommunications networks. In each there is a specific standing capability we would need before taking the work, not a gap we could close during it: a clinical safety officer and a live hazard log for health, computerised system validation for GxP work, certainty that privilege holds inside the system for law firms, an operations research bench for routing and scheduling, and network security engineers for telecoms. A supplier offering to acquire those during your programme is asking you to fund their learning. Each entry says who to look for instead.

How does agentic AI delivery differ between regulated and unregulated sectors?

Mostly in who has to be in the design and what has to be provable. Regulated programmes are gated by governance rather than technology: your second line, actuarial or safety function designs the controls rather than reviewing them, the human-in-the-loop boundary sits further towards people, evidence has to be emitted as the system runs, and in financial services procurement and supplier onboarding add 8–12 weeks before work starts. In lighter-regulated sectors such as retail the floor is lower but not absent, because the CMA now enforces consumer law directly and anything an agent writes for a customer is a commercial practice by the trader. Sequencing differs too. Customer-facing work waits for the evidence base, so the early wins are internal.

What if our sector is not one of the four you list?

Ask on a call whether the constraints still rhyme, and we will tell you which of two cases you are in. Much of what looks like sector work is not. Corporate, delivery and knowledge work in a pharmaceutical company or a telco is taken on the same terms as in any other large organisation, and the document-and-exception pattern behind our insurance work recurs almost everywhere. Where the work needs a standing capability such as clinical safety, we say no rather than claim evidence we do not hold, and we tell you what to look for instead. The list is a current position, and a sector earns a page when we can point at named work in it.

Do UK regulators have specific rules for AI agents?

Mostly no, and that fact is more useful than it sounds. The FCA and the PRA have said they do not intend to write a separate AI rulebook, so the obligations firms already answer to apply to agents in full. UK government work is gated by duties that already exist: algorithmic transparency records, automated decision-making law and procurement. In retail, the CMA enforces the unfair commercial practices rules whether a person or a model wrote the words. An agent is never a new category of thing to be permitted, only a new way of meeting or breaching rules that already bind you, so the first job everywhere is mapping which regimes reach each workflow.

Do agentic AI use cases transfer between sectors?

The patterns transfer; the constraints do not. The same shapes recur in every sector we work in: document-heavy intake, knowledge retrieval across fragmented estates, exception handling, summarisation and evidence gathering. The pipeline behind our specialty insurance proof of concept, which extracts each document to an inspectable form, normalises, enriches and scores confidence from provenance, is the same shape as KYC file assembly in a bank or customs paperwork in a logistics business. What changes is everything around it: which regulator reaches the workflow, where the human decision must sit, and what evidence the system has to produce as it runs. That is why the sector pages spend more words on constraints than on technology.

How can we tell if an AI consultancy's sector experience is real?

Ask for named engagements, what each one actually was, and which parts transfer to you, then watch how the answers are labelled. A proof of concept described as production, or a founder's employment history presented as firm clients, tells you how the rest of the relationship will run. Tenhaw draws those lines in public: each sector page carries named work, roles held are labelled separately from clients, proofs of concept are called exactly that, and the prices are published so anyone can check them. The public sector page names the portfolio office Tenhaw ran across 19 projects for Tecknuovo, including delivery for HMRC, the MOD and Thames Water, and says exactly what our role in it was.

Do agents pay back faster in some sectors than others?

Yes, and the difference is structural rather than technical. Retail, consumer and media see it soonest: volume is high, feedback loops are short, and decisions in merchandising, content and service triage are frequently reversible, so a programme can show results inside a single trading cycle. Industrial, energy and infrastructure sit at the opposite pole, where decisions are expensive to reverse, value concentrates in engineering knowledge work, simulation and planning, and the business case is measured in years rather than quarters. Financial services sits between them, with plenty of volume and a governance gate in front of anything a customer sees. Speed of return is a property of the sector's decisions, not of the model.

Does an agentic programme cost more in a regulated sector?

No. The published prices carry no regulated-sector premium, so the AI Readiness Audit is £44,000 fixed over four weeks and an Agentic Proof of Concept is £20k–£55k over two to four weeks, in a bank exactly as in a retailer. What regulation changes is the calendar around the work and who sits in the design with us. In financial services, procurement and supplier onboarding realistically add 8–12 weeks before anything starts. In retail, peak trading freezes remove roughly a quarter of the delivery year. In government, assurance is departmental, so the approval path has to be mapped before the plan is written. Budget the elapsed time rather than a bigger fee.

Which of our own functions has to be in the design from week one?

Whichever one would otherwise review you at the end, and the sector decides who that is. In a bank or insurer it is second-line risk, joined by the actuarial function the moment anything feeds pricing, technical provisions or an internal model. In retail, consumer and media it is your DPO, plus legal for where puffery ends and a misleading claim begins. In industrial and energy it is OT security, which designs any write path into the control domain, and the safety function, which owns change control. In government it is whoever owns the transparency record and your departmental assurance route. Designing with those people costs far less than being reviewed by them.

What happens when an agent's autonomy widens after the pilot?

This is the failure that recurs in every sector we work in, and it arrives by drift rather than by decision. In retail the DPIA was completed once for a narrow pilot and never revisited when autonomy widened, which is the change that altered the risk. In industrial and energy a tool arrives as decision support, becomes the thing operators rely on, and no management-of-change assessment fires because nothing in the control system changed. In insurance an agent starts influencing risk selection, which is precisely what a binding authority governs, without the binder being reopened. The remedy in all three is to make the autonomy boundary explicit at design time, so crossing it has to be somebody's decision.

How many regulations does an AI programme have to answer to in our sector?

Nineteen regimes sit behind the four sectors, and no single organisation faces all of them. Financial services carries seven: the FCA and the PRA, Consumer Duty, SS1/23 model risk, operational resilience, DORA, Solvency II and Solvency UK, and Lloyd's delegated authority. Retail, consumer and media carries three, industrial and energy three, and the public sector six. Each is set out on its sector page with what it asks of an agentic system, where programmes fall down against it, what our method does and where our own evidence stops. Only the regimes reaching the first workflow you automate decide your workload. That is a smaller number than any of those totals, which is why sequencing matters more than ambition.

We span three of these sectors. Do we run one AI programme or three?

One method, three constraint maps. The technology underneath the four sectors is close to identical, so the platform decision, the evaluation approach and the delivery method are shared, and duplicating them per division is how a group ends up with three half-built stacks. The constraint map and the adoption plan cannot be shared. Head office knowledge work and frontline store or contact-centre operations have almost nothing in common, and running them as one programme is a reliable way to fail at both. Sequence the first build where decisions are high-volume and cheaply reversible, prove it there, then carry the pattern rather than the design into the harder division.