Sector · Public Sector and Government

Agentic transformation in Public Sector and Government

Published duties, published routes to market, and where our evidence stops.

projects overseen by the portfolio office we built from nothing at Tecknuovo
19
running it live, and coaching the delivery leads who took it over
9 months
agentic systems Tenhaw has delivered inside a government department
None
Work delivered at
Tecknuovo

The short answer

Agentic delivery in UK government is not gated by a new AI rulebook. It is gated by three published duties that already exist: what an organisation has to record in public about an algorithmic tool, what may be decided about a citizen without meaningful human involvement, and how the work is bought. The AI Playbook for the UK Government sits over the top of those, and departments now run their own digital assurance rather than passing through a central Cabinet Office control.

Departments and arm's length bodies

The Algorithmic Transparency Recording Standard is mandatory for central government departments and for arm's length bodies that deliver public services or engage directly with the public, so the tool's description is a public document rather than an internal one. Section 80 of the Data (Use and Access) Act 2025 replaced Article 22 of the UK GDPR with Articles 22A to 22D, which turn on whether there is meaningful human involvement in a significant decision. The Digital, Data and Technology Playbook still applies on a comply or explain basis, and since 1 April 2026 digital and technology assurance runs through the Digital Assurance Playbook inside your own organisation.

Suppliers delivering into departments

The route to market shapes the engagement before the technology does. G-Cloud 14 is a catalogue for cloud hosting, software and support. Digital Outcomes and Specialists 7 went live on 30 January 2026 as an open framework under the Procurement Act 2023, in four lots, and every call-off runs through a further competition, with no direct award. Both are now run by the Government Commercial Agency, which Crown Commercial Service became on 1 April 2026. What you build also has to be describable in your client's transparency record, which is a delivery requirement rather than a marketing one.

Tenhaw has not delivered an agentic system inside a government department. What we hold is delivery-transformation exposure to public sector programmes through a supplier, not agentic delivery to a department: at Tecknuovo we built a centralised portfolio office from nothing and ran it across 19 projects, including engagements delivering to HMRC, the MOD and Thames Water. If you need a supplier who has already taken an agentic system through a department's assurance, say so on the call and we will tell you that we are not it yet.

Regulation in public sector and government

The constraints that decide the sequence

Not the ones that sound good in a deck. These determine which workflows can move to agents at all, and in what order.

01

The public record is part of the deliverable

In most sectors the description of what a system does is internal. Here, for organisations in scope of the Algorithmic Transparency Recording Standard, it is published: what the tool is, why it is used, the data behind it and the human oversight around it. A supplier who cannot produce those facts as an output of delivery leaves the organisation writing them afterwards from a sales deck.

02

A decision about a citizen is a different class of decision

Section 80 of the Data (Use and Access) Act 2025 replaced Article 22 of the UK GDPR with Articles 22A to 22D, and the test that matters is meaningful human involvement in a significant decision. A caseworker looking at a recommendation, a confidence score and a queue target is the arrangement that test exists to catch, so where the human sits and what they can see is a design question rather than a policy one.

03

Assurance moved inside the organisation, it did not disappear

Most Cabinet Office spend controls ceased as a requirement on 1 April 2026, and digital and technology assurance now runs through the Digital Assurance Playbook inside each organisation. The approval path is departmental, it is not the same in any two departments, and a programme plan that assumes the old central gate is planning against a process that no longer exists.

04

The route to market decides the shape of the work

A catalogue framework buys cloud hosting, software and support. An outcomes framework buys a team against a defined outcome, through a further competition, with no direct award. Those are different engagements with different pricing and different evidence, and choosing the route after the design has already been agreed is how a proof of concept ends up in the wrong contractual vehicle.

05

Capability has to be left behind

The Digital, Data and Technology Playbook asks for outcome-based specifications, delivery model assessments and attention to legacy and lock-in, and the AI Playbook asks that organisations have the skills to run what they adopt. A supplier whose value depends on remaining indispensable is arguing against the policy the buyer is measured on.

06

Scrutiny arrives from outside the programme

Contracts are published under the Procurement Act 2023, transparency records are public, and select committees, the National Audit Office and journalists read both. Evidence of governance is part of the deliverable rather than an internal comfort, which is exactly what we found running a portfolio office over public sector delivery at Tecknuovo.

Data residency, model risk and auditability are questions about us as much as about your estate. Our security and assurance position says what we hold today and what we do not.

Sequencing

Where agents land first, and where they should not

Both halves matter. A supplier who only shows you the left-hand column is selling you the second year of the programme as though it were the first.

Start here

Where the value is real and the risk is contained.

  1. 1Internal knowledge retrieval across policy, guidance and procedure that is already published
  2. 2Casework preparation and triage, with the decision itself left with the caseworker
  3. 3Drafting and correspondence support, with a named human accountable for what goes out
  4. 4Portfolio and delivery reporting across a programme, the workflow behind our Tecknuovo portfolio office
  5. 5Assurance and audit evidence gathering, where the record is the product
  6. 6Developer and delivery workflow inside your own teams, where the risk surface is contained

Real constraints

The things that will bite, and worth pricing in before you sign.

  • Anything that decides or materially shapes an outcome for a citizen needs the Article 22A to 22D safeguards designed in from the first week, not added at go-live
  • Tenhaw has no agentic delivery record inside a government department, and you should weigh that against suppliers who do
  • If your organisation is in scope of the transparency standard, the record has to be producible from the running system, which is a build requirement rather than a documentation task
  • Frameworks are a route in, not a shortcut: an outcomes call-off runs through a further competition and no agreement here permits a direct award
  • Departmental assurance replaced the central spend control, so the approval path has to be mapped before the plan is written
  • What Tenhaw holds as a supplier, including what is certified and what is in progress, is published on the security page
Regulatory

What gates an agentic programme in government

No new AI rulebook, and no shortage of duties. What has to be published about the tool, what may be decided about a citizen without a human, the assurance departments now run themselves, and the route the work is bought through.

The Digital, Data and Technology Playbook and the routes to market

Mandated for central government departments and their arm's length bodies on a comply or explain basis, with the wider public sector expected to take it into account. It governs how digital projects are assessed, procured and delivered, which makes it the document a supplier is measured against before anyone looks at the technology.

What it requires of an agent
Eleven policies, of which four decide the shape of an agentic programme: a commercial pipeline published well ahead of the work, a delivery model assessment with a should cost model, specifications that are outcome-based rather than prescriptive, and testing and learning where a service is delivered in a new way. The routes to market carry their own shape. G-Cloud 14 (RM1557.14) is a catalogue of cloud hosting, cloud software and cloud support. Digital Outcomes and Specialists 7 (RM1043.9) went live on 30 January 2026 as an open framework under the Procurement Act 2023, in four lots covering outcomes, capability and delivery partners, specialists, and user research, and every call-off runs through a further competition.
Where programmes fall down
A supplier writes an agentic proposal against a prescriptive specification the buyer was never meant to write, or answers a specialists lot with what is really an outcomes engagement, and the mismatch surfaces in the call-off rather than in the pitch. The other pattern is a proof of concept bought through a cloud catalogue as though it were software, then found to be a services engagement when the commercial team reads the terms.
What our method does about it
We ask which route the work will be bought through before we scope it, because an outcomes lot and a specialists lot produce different teams, different pricing and different evidence. Both of our entry rungs are fixed price and time-boxed, which is the shape an outcome-based specification is asking for.

Where our evidence stops: We are not procurement advisers. Which agreement and lot you use, and whether your requirement is a covered procurement at all, are your commercial function's decisions. Ask on the call which routes to market Tenhaw can be bought through today, because the answer changes as frameworks reopen.

The AI Playbook for the UK Government

Published by the Government Digital Service on 10 February 2025, for civil servants building or buying AI and for the suppliers working with them. It updates and expands the Generative AI Framework for HMG and covers AI beyond generative models. The Digital Assurance Playbook asks assurers to check that initiatives using AI follow it.

What it requires of an agent
Ten principles. Four of them decide a build: knowing what AI is and what its limitations are, using AI lawfully, ethically and responsibly, having meaningful human control at the right stages, and working with commercial colleagues from the start. It asks that humans validate high-risk decisions influenced by AI, that products are tested before deployment, and that assurance and checks continue on the live tool rather than stopping at go-live.
Where programmes fall down
Meaningful human control is claimed and never designed. A person sits at the end of the workflow with no time, no context and no route to disagree, which is review theatre rather than control, and it is visible as such the first time anyone examines a decision. The second failure is commercial engagement arriving after the technical design, by which point the design has already decided what the contract has to say about model changes, data and exit.
What our method does about it
Human control points are named in the decision inventory before anything is built, with the information the reviewer needs at that point and a recorded route to overturn the output. We treat the Playbook's principles as acceptance criteria for the audit rather than as a document to cite in a bid, and we bring the commercial question forward because it constrains the architecture more than most technical choices do.

Where our evidence stops: Tenhaw has read the Playbook and can design to it. No department has assured a Tenhaw system against it, because we have not delivered one inside a department. Those are different claims and you should make every supplier, including us, say which one they are making.

The Algorithmic Transparency Recording Standard

Mandatory for central government departments and for arm's length bodies that deliver public services or engage directly with the public, and recommended for the wider public sector. A scope and exemptions policy published in December 2024 sets out which organisations and which algorithmic tools it is a requirement for.

What it requires of an agent
A published record of the algorithmic tool, in a complete, open, understandable and free format: what it is, why the organisation is using it, how it works, the data behind it and the human oversight around it. Because the record is public, it is the first artefact a journalist, a select committee or a claimant's solicitor will read, and it is read alongside the system rather than instead of it.
Where programmes fall down
The record is written months after go-live by someone who was not in the build, from supplier material, because nobody made those facts a delivery output. The subtler failure is a record that cannot be kept true: an agentic workflow whose prompts, retrieval corpus and tool permissions change every few weeks, described by a record written for the version that launched.
What our method does about it
We treat the record's fields as build outputs. The model and decision inventory the audit produces already holds purpose, data sources, models, human oversight points and named owners, which is most of what the standard asks for, and change control fires on a prompt or corpus change rather than only on a model upgrade, so the published record can be kept true instead of re-derived once a year.

Where our evidence stops: The record belongs to the organisation and publishing it is the organisation's decision. Tenhaw has never produced one on a live engagement, because we have not delivered inside an organisation in scope. What we can tell you is what the standard asks for and how to make a system emit it.

Automated decisions about citizens, under the Data (Use and Access) Act

Any controller taking significant decisions about people, which in government means most casework. Section 80 of the Data (Use and Access) Act 2025 replaced Article 22 of the UK GDPR with new Articles 22A to 22D, and the UK GDPR's other duties, including the data protection impact assessment in Article 35, apply underneath as before.

What it requires of an agent
A significant decision is one producing a legal effect for the person or a similarly significant effect. Whether it is taken solely by automated means turns on meaningful human involvement, judged including by how far the decision is reached by profiling. Where there is none, safeguards are required: information about the decision, the ability to make representations, human intervention by the controller, and the ability to contest the outcome. Special category data narrows it further, needing explicit consent or a specific legal footing before a solely automated significant decision can be taken at all.
Where programmes fall down
Human involvement is asserted rather than designed, and the assertion does not survive contact with the facts: the reviewer sees a recommendation and a score, has a handling time target, and overturns almost nothing. The other failure is a contest route that exists on paper and cannot answer the citizen's actual question, because the system kept no record of what drove the output and the retrieval corpus has moved on since.
What our method does about it
For anything touching a citizen outcome we design the human involvement so it can change the answer: the reviewer sees the evidence, not a score, disagreement is recorded as an outcome, and the reasons trail is retained as part of the workflow rather than in logs with a thirty day retention. We sequence citizen-facing decisioning last, after internal work, because the evidence base you will need to defend it is far cheaper to build where nobody is affected while you are learning.

Where our evidence stops: Tenhaw is not your data protection officer and gives no legal advice. Whether a decision is significant, and whether your human involvement is meaningful, are calls for your DPO and your legal advisers. We would rather have them in the design session than in the approval queue, and we have not run this design inside a department yet.

Cabinet Office spend controls, and the assurance that replaced them

Central government departments and their arm's length bodies. Most Cabinet Office spend controls ceased as a requirement on 1 April 2026, with the advertising, marketing and communications control the exception. Digital and technology assurance moved on the same date to the Digital Assurance Playbook, published by the Department for Science, Innovation and Technology.

What it requires of an agent
Organisations now design their own assurance rather than passing through a central control, with three levels of it: operational, senior management and independent review. A forward pipeline of digital and technology spend is still shared, for initiatives above £5 million whole life cost and at a £0 threshold for cryptographic products. Assurers are asked to check that initiatives using AI follow the AI Playbook for the UK Government, which is how a voluntary-sounding document becomes something your gate reviewer holds you to.
Where programmes fall down
Two mirror-image mistakes. A supplier plans a bid around a central control that no longer exists, and a buyer reads the removal of the control as the removal of the assurance. The practical consequence is the same either way: the approval path is now departmental, it differs between organisations, and nobody has mapped it before the work is meant to start.
What our method does about it
We ask who approves at each stage in your organisation before we agree a plan, and we design the artefacts to be the ones your own assurance asks for rather than a separate pack produced for us. The audit's outputs, a decision inventory, an agreed autonomy boundary and an evidence trail the system emits as it runs, are close to what three levels of assurance ask for at each level, which is deliberate.

Where our evidence stops: We do not sit in your approval chain and we hold no view on your accounting officer's duties. Where an initiative needs Treasury approval, that is a business case discipline we can supply evidence into rather than one we own. We have supported assurance evidence in a supplier's portfolio office, not inside a department's own gate process.

The Procurement Act 2023 and what it publishes

Contracting authorities across the public sector, live since 24 February 2025 alongside the Procurement Regulations 2024. It applies to the agentic work as it applies to everything else, and it is the reason the engagement is a public record rather than a private arrangement.

What it requires of an agent
Notices through the commercial lifecycle: tender notices, transparency notices, contract award notices and contract change notices, with conflicts of interest identified and mitigated, rules of their own below threshold, and remedies where the rules are broken. In practice the department has to be able to say what it bought, why, and what changed, and the answer is published.
Where programmes fall down
Scope creeps from the thing that was competed into the thing that turned out to be needed. Agentic programmes do this by default, because a proof of concept that works produces an immediate request to productionise it, and productionising is usually a different requirement with a different value. Handled late, that is a contract change notice and an awkward conversation; handled at the start, it is simply the next procurement.
What our method does about it
We scope the audit and the proof of concept as separate fixed-price outcomes with their own end points, and we say at the outset that productionising is a separate decision with its own commercial route. We work that way everywhere. In a contracting authority it is the difference between a clean award and a modification nobody planned for.

Where our evidence stops: We are not procurement lawyers and we do not advise on the Act. What may be awarded, and how, belongs to your commercial and legal functions. Our contribution is not creating a modification you did not plan for, and telling you early when the work we are describing is a second procurement rather than an extension of the first.

Tenhaw builds agentic systems and the operating models around them, and works alongside the risk, compliance, legal and actuarial functions who own the interpretation of these regimes. Our security and assurance position states what we hold today and what is still in progress.

Evidence

What we have done here

Named clients where we have permission to name them, and the evidence basis stated on every one.

What our public sector evidence is, and what it is not

At Tecknuovo, a consultancy, we built a centralised portfolio management office from nothing and ran it live across 19 projects, including engagements delivering to HMRC, the MOD and Thames Water. That is delivery-transformation exposure to public sector programmes through a supplier, not agentic delivery to a department. Tecknuovo's own teams delivered those projects; our work was the office that made them visible, comparable and manageable. Nothing in that portfolio was a model, so we make no AI governance claim from it, and we have never produced an Algorithmic Transparency Recording Standard record on a live engagement. If you need a supplier who has already taken an agentic system through a department's own assurance, we are not it yet.

Public Sector and Government: your questions

Does Tenhaw work with the public sector?

Not yet, in the sense a department would mean by it. Almost none of Tenhaw's work is public sector. Our evidence here is delivery-transformation exposure to public sector programmes through a supplier, not agentic delivery to a department: at Tecknuovo, a consultancy, we built a centralised portfolio management office from nothing over nine months and ran it live across 19 projects, including engagements delivering to HMRC, the MOD and Thames Water, while coaching the junior delivery leads who took it over. Tecknuovo's own teams delivered those projects. Our work was the office that made them visible, comparable and manageable. Nothing in that portfolio was a model and we make no AI governance claim from it. If you want a supplier who has taken an agentic system through a department's own assurance, we are not that supplier today.

What does the Algorithmic Transparency Recording Standard require of an AI supplier?

Strictly, nothing: the standard binds the organisation, not the supplier. In practice it decides what a supplier has to produce. The standard is mandatory for central government departments and for arm's length bodies that deliver public services or engage directly with the public, and it asks for a published record of what the algorithmic tool is, why the organisation is using it, how it works, the data behind it and the human oversight around it. That means the facts have to exist inside delivery: purpose, data sources, models and versions, human oversight points and named owners, all current rather than as at launch. The test to apply to a supplier is simple. Ask whether their build produces those fields as outputs, and what happens to the published record when a prompt or a retrieval corpus changes next month.

Can a government department let an AI agent decide a case?

It depends on whether the decision is significant and whether a human is meaningfully involved. Section 80 of the Data (Use and Access) Act 2025 replaced Article 22 of the UK GDPR with Articles 22A to 22D. A significant decision is one with a legal effect or a similarly significant effect on the person, and whether it counts as solely automated turns on meaningful human involvement, judged including by how far the decision is reached through profiling. Where there is no meaningful human involvement, safeguards are required: information about the decision, the ability to make representations, human intervention by the controller and the ability to contest the outcome. Special category data narrows it further, needing explicit consent or a specific legal footing. The design consequence is that a caseworker with a recommendation, a score and a handling time target is probably not meaningful involvement, so the reviewer has to see the evidence, be able to disagree, and have that disagreement recorded. Tenhaw is not your DPO and this is not legal advice.

How is agentic AI bought in UK government?

Through the same routes as other digital work, and the route shapes the engagement. G-Cloud 14 (RM1557.14) is a catalogue for cloud hosting, cloud software and cloud support. Digital Outcomes and Specialists 7 (RM1043.9) went live on 30 January 2026 as an open framework under the Procurement Act 2023, with four lots covering digital outcomes, capability and delivery partners, specialists, and user research, and it requires a further competition rather than a direct award. Both are run by the Government Commercial Agency, which Crown Commercial Service became on 1 April 2026. Over the top sits the Digital, Data and Technology Playbook, which asks for outcome-based specifications and a delivery model assessment on a comply or explain basis. The practical advice is to settle the route before the design, because an outcomes lot and a specialists lot produce different teams, different pricing and different evidence.

Did Cabinet Office spend controls end, and what replaced them for AI projects?

Most Cabinet Office spend controls ceased as a requirement on 1 April 2026, with the advertising, marketing and communications control the exception. Digital and technology assurance did not end with them: it moved to the Digital Assurance Playbook, published by the Department for Science, Innovation and Technology on the same date, under which organisations design their own assurance across three levels, operational, senior management and independent review, and still share a forward pipeline of digital and technology spend above £5 million whole life cost, with a £0 threshold for cryptographic products. For AI specifically, assurers are asked to check that the initiative follows the AI Playbook for the UK Government. So the gate is now inside your organisation rather than in the centre, it is not identical between departments, and a delivery plan that has not mapped it is planning against a process that no longer exists.

What should a department ask an agentic AI supplier to evidence?

Five things, all of which should exist before a contract is signed. Which decisions the agent may take and which need a human, written down as an inventory rather than described in a workshop. Where the human sits, what they see at that point, and how their disagreement is recorded, because meaningful human involvement is a design property and not a claim. How the transparency record will be produced and kept true when prompts, corpora and model versions change. What the system emits as evidence while it runs, as opposed to what can be reconstructed from logs afterwards. And what happens on exit: whose the prompts, evaluation sets and retrieval corpora are, and what breaks if the model provider changes its terms. Ask every supplier, us included, which of those they have done inside a department and which they have only designed.

Has Tenhaw delivered an AI system inside a government department?

No. Tenhaw has not delivered an agentic system inside a government department, and we have not produced an Algorithmic Transparency Recording Standard record on a live engagement. Our agentic evidence is proofs of concept: an AI voice-insights proof of concept at HSBC, and a live specialty insurance engagement running a two-week proof of concept into a team standing up to productionise it. Our public sector evidence is the Tecknuovo portfolio office, which is delivery-transformation exposure to public sector programmes through a supplier, not agentic delivery to a department.

Thirty minutes on Public Sector and Government, with James Rooney

We'll be specific about what applies in your sector and what does not, and you'll leave with a rough scope whether you engage us or not.

30 minutesWith James personallyNo obligation

Most organisations start with a fixed-price Agent-Readiness Audit · £30k–£90k · 6–8 weeks