Regulatory
No new AI rulebook, and no shortage of duties. What has to be published about the tool, what may be decided about a citizen without a human, the assurance departments now run themselves, and the route the work is bought through.
Mandated for central government departments and their arm's length bodies on a comply or explain basis, with the wider public sector expected to take it into account. It governs how digital projects are assessed, procured and delivered, which makes it the document a supplier is measured against before anyone looks at the technology.
- What it requires of an agent
- Eleven policies, of which four decide the shape of an agentic programme: a commercial pipeline published well ahead of the work, a delivery model assessment with a should cost model, specifications that are outcome-based rather than prescriptive, and testing and learning where a service is delivered in a new way. The routes to market carry their own shape. G-Cloud 14 (RM1557.14) is a catalogue of cloud hosting, cloud software and cloud support. Digital Outcomes and Specialists 7 (RM1043.9) went live on 30 January 2026 as an open framework under the Procurement Act 2023, in four lots covering outcomes, capability and delivery partners, specialists, and user research, and every call-off runs through a further competition.
- Where programmes fall down
- A supplier writes an agentic proposal against a prescriptive specification the buyer was never meant to write, or answers a specialists lot with what is really an outcomes engagement, and the mismatch surfaces in the call-off rather than in the pitch. The other pattern is a proof of concept bought through a cloud catalogue as though it were software, then found to be a services engagement when the commercial team reads the terms.
- What our method does about it
- We ask which route the work will be bought through before we scope it, because an outcomes lot and a specialists lot produce different teams, different pricing and different evidence. Both of our entry rungs are fixed price and time-boxed, which is the shape an outcome-based specification is asking for.
Where our evidence stops: We are not procurement advisers. Which agreement and lot you use, and whether your requirement is a covered procurement at all, are your commercial function's decisions. Ask on the call which routes to market Tenhaw can be bought through today, because the answer changes as frameworks reopen.
Published by the Government Digital Service on 10 February 2025, for civil servants building or buying AI and for the suppliers working with them. It updates and expands the Generative AI Framework for HMG and covers AI beyond generative models. The Digital Assurance Playbook asks assurers to check that initiatives using AI follow it.
- What it requires of an agent
- Ten principles. Four of them decide a build: knowing what AI is and what its limitations are, using AI lawfully, ethically and responsibly, having meaningful human control at the right stages, and working with commercial colleagues from the start. It asks that humans validate high-risk decisions influenced by AI, that products are tested before deployment, and that assurance and checks continue on the live tool rather than stopping at go-live.
- Where programmes fall down
- Meaningful human control is claimed and never designed. A person sits at the end of the workflow with no time, no context and no route to disagree, which is review theatre rather than control, and it is visible as such the first time anyone examines a decision. The second failure is commercial engagement arriving after the technical design, by which point the design has already decided what the contract has to say about model changes, data and exit.
- What our method does about it
- Human control points are named in the decision inventory before anything is built, with the information the reviewer needs at that point and a recorded route to overturn the output. We treat the Playbook's principles as acceptance criteria for the audit rather than as a document to cite in a bid, and we bring the commercial question forward because it constrains the architecture more than most technical choices do.
Where our evidence stops: Tenhaw has read the Playbook and can design to it. No department has assured a Tenhaw system against it, because we have not delivered one inside a department. Those are different claims and you should make every supplier, including us, say which one they are making.
Mandatory for central government departments and for arm's length bodies that deliver public services or engage directly with the public, and recommended for the wider public sector. A scope and exemptions policy published in December 2024 sets out which organisations and which algorithmic tools it is a requirement for.
- What it requires of an agent
- A published record of the algorithmic tool, in a complete, open, understandable and free format: what it is, why the organisation is using it, how it works, the data behind it and the human oversight around it. Because the record is public, it is the first artefact a journalist, a select committee or a claimant's solicitor will read, and it is read alongside the system rather than instead of it.
- Where programmes fall down
- The record is written months after go-live by someone who was not in the build, from supplier material, because nobody made those facts a delivery output. The subtler failure is a record that cannot be kept true: an agentic workflow whose prompts, retrieval corpus and tool permissions change every few weeks, described by a record written for the version that launched.
- What our method does about it
- We treat the record's fields as build outputs. The model and decision inventory the audit produces already holds purpose, data sources, models, human oversight points and named owners, which is most of what the standard asks for, and change control fires on a prompt or corpus change rather than only on a model upgrade, so the published record can be kept true instead of re-derived once a year.
Where our evidence stops: The record belongs to the organisation and publishing it is the organisation's decision. Tenhaw has never produced one on a live engagement, because we have not delivered inside an organisation in scope. What we can tell you is what the standard asks for and how to make a system emit it.
Any controller taking significant decisions about people, which in government means most casework. Section 80 of the Data (Use and Access) Act 2025 replaced Article 22 of the UK GDPR with new Articles 22A to 22D, and the UK GDPR's other duties, including the data protection impact assessment in Article 35, apply underneath as before.
- What it requires of an agent
- A significant decision is one producing a legal effect for the person or a similarly significant effect. Whether it is taken solely by automated means turns on meaningful human involvement, judged including by how far the decision is reached by profiling. Where there is none, safeguards are required: information about the decision, the ability to make representations, human intervention by the controller, and the ability to contest the outcome. Special category data narrows it further, needing explicit consent or a specific legal footing before a solely automated significant decision can be taken at all.
- Where programmes fall down
- Human involvement is asserted rather than designed, and the assertion does not survive contact with the facts: the reviewer sees a recommendation and a score, has a handling time target, and overturns almost nothing. The other failure is a contest route that exists on paper and cannot answer the citizen's actual question, because the system kept no record of what drove the output and the retrieval corpus has moved on since.
- What our method does about it
- For anything touching a citizen outcome we design the human involvement so it can change the answer: the reviewer sees the evidence, not a score, disagreement is recorded as an outcome, and the reasons trail is retained as part of the workflow rather than in logs with a thirty day retention. We sequence citizen-facing decisioning last, after internal work, because the evidence base you will need to defend it is far cheaper to build where nobody is affected while you are learning.
Where our evidence stops: Tenhaw is not your data protection officer and gives no legal advice. Whether a decision is significant, and whether your human involvement is meaningful, are calls for your DPO and your legal advisers. We would rather have them in the design session than in the approval queue, and we have not run this design inside a department yet.
Central government departments and their arm's length bodies. Most Cabinet Office spend controls ceased as a requirement on 1 April 2026, with the advertising, marketing and communications control the exception. Digital and technology assurance moved on the same date to the Digital Assurance Playbook, published by the Department for Science, Innovation and Technology.
- What it requires of an agent
- Organisations now design their own assurance rather than passing through a central control, with three levels of it: operational, senior management and independent review. A forward pipeline of digital and technology spend is still shared, for initiatives above £5 million whole life cost and at a £0 threshold for cryptographic products. Assurers are asked to check that initiatives using AI follow the AI Playbook for the UK Government, which is how a voluntary-sounding document becomes something your gate reviewer holds you to.
- Where programmes fall down
- Two mirror-image mistakes. A supplier plans a bid around a central control that no longer exists, and a buyer reads the removal of the control as the removal of the assurance. The practical consequence is the same either way: the approval path is now departmental, it differs between organisations, and nobody has mapped it before the work is meant to start.
- What our method does about it
- We ask who approves at each stage in your organisation before we agree a plan, and we design the artefacts to be the ones your own assurance asks for rather than a separate pack produced for us. The audit's outputs, a decision inventory, an agreed autonomy boundary and an evidence trail the system emits as it runs, are close to what three levels of assurance ask for at each level, which is deliberate.
Where our evidence stops: We do not sit in your approval chain and we hold no view on your accounting officer's duties. Where an initiative needs Treasury approval, that is a business case discipline we can supply evidence into rather than one we own. We have supported assurance evidence in a supplier's portfolio office, not inside a department's own gate process.
Contracting authorities across the public sector, live since 24 February 2025 alongside the Procurement Regulations 2024. It applies to the agentic work as it applies to everything else, and it is the reason the engagement is a public record rather than a private arrangement.
- What it requires of an agent
- Notices through the commercial lifecycle: tender notices, transparency notices, contract award notices and contract change notices, with conflicts of interest identified and mitigated, rules of their own below threshold, and remedies where the rules are broken. In practice the department has to be able to say what it bought, why, and what changed, and the answer is published.
- Where programmes fall down
- Scope creeps from the thing that was competed into the thing that turned out to be needed. Agentic programmes do this by default, because a proof of concept that works produces an immediate request to productionise it, and productionising is usually a different requirement with a different value. Handled late, that is a contract change notice and an awkward conversation; handled at the start, it is simply the next procurement.
- What our method does about it
- We scope the audit and the proof of concept as separate fixed-price outcomes with their own end points, and we say at the outset that productionising is a separate decision with its own commercial route. We work that way everywhere. In a contracting authority it is the difference between a clean award and a modification nobody planned for.
Where our evidence stops: We are not procurement lawyers and we do not advise on the Act. What may be awarded, and how, belongs to your commercial and legal functions. Our contribution is not creating a modification you did not plan for, and telling you early when the work we are describing is a second procurement rather than an extension of the first.
Tenhaw builds agentic systems and the operating models around them, and works alongside the risk, compliance, legal and actuarial functions who own the interpretation of these regimes. Our security and assurance position states what we hold today and what is still in progress.