Sector · Public Sector and Government

Agentic transformation in Public Sector and Government

Published duties, published routes to market, and where our evidence stops.
projects overseen by the portfolio office we built from nothing at Tecknuovo
19
running it live, and coaching the delivery leads who took it over
9 months
agentic systems Tenhaw has delivered inside a government department
None
Work delivered atTecknuovo
On this page

The short answer

Agentic delivery in UK government is not gated by a new AI rulebook. It is gated by three published duties that already exist: what an organisation has to record in public about an algorithmic tool, what may be decided about a citizen without meaningful human involvement, and how the work is bought. The AI Playbook for the UK Government sits over the top of those, and departments now run their own digital assurance rather than passing through a central Cabinet Office control.

Departments and arm's length bodies

The Algorithmic Transparency Recording Standard is mandatory for central government departments and for arm's length bodies that deliver public services or engage directly with the public, so the tool's description is a public document rather than an internal one. Section 80 of the Data (Use and Access) Act 2025 replaced Article 22 of the UK GDPR with Articles 22A to 22D, which turn on whether there is meaningful human involvement in a significant decision. The Digital, Data and Technology Playbook still applies on a comply or explain basis, and since 1 April 2026 digital and technology assurance runs through the Digital Assurance Playbook inside your own organisation.

Suppliers delivering into departments

The route to market shapes the engagement before the technology does. G-Cloud 14 is a catalogue for cloud hosting, software and support. Digital Outcomes and Specialists 7 went live on 30 January 2026 as an open framework under the Procurement Act 2023, in four lots, and every call-off runs through a further competition, with no direct award. Both are now run by the Government Commercial Agency, which Crown Commercial Service became on 1 April 2026. What you build also has to be describable in your client's transparency record, which is a delivery requirement rather than a marketing one.

Tenhaw's public sector record is portfolio delivery. At Tecknuovo we were the portfolio manager, hands on under the contract, building a centralised portfolio office from nothing and running it live across 19 projects, including engagements delivering to HMRC, the MOD and Thames Water, with Tecknuovo's own teams delivering the projects themselves. Tenhaw is a UK agentic AI consultancy and delivery partner: we design and build agentic operating models, and we leave the capability behind rather than the dependency.

That is the short answer for the sector. The call is where it gets specific to your organisation.

Talk it through
Regulation in public sector and government

The constraints that decide the sequence

Not the ones that sound good in a deck. These determine which workflows can move to agents at all, and in what order.

01

The public record is part of the deliverable

In most sectors the description of what a system does is internal. Here, for organisations in scope of the Algorithmic Transparency Recording Standard, it is published: what the tool is, why it is used, the data behind it and the human oversight around it. A supplier who cannot produce those facts as an output of delivery leaves the organisation writing them afterwards from a sales deck.

02

A decision about a citizen is a different class of decision

Section 80 of the Data (Use and Access) Act 2025 replaced Article 22 of the UK GDPR with Articles 22A to 22D, and the test that matters is meaningful human involvement in a significant decision. A caseworker looking at a recommendation, a confidence score and a queue target is the arrangement that test exists to catch, so where the human sits and what they can see is a design question rather than a policy one.

03

Assurance moved inside the organisation, it did not disappear

Most Cabinet Office spend controls ceased as a requirement on 1 April 2026, and digital and technology assurance now runs through the Digital Assurance Playbook inside each organisation. The approval path is departmental, it is not the same in any two departments, and a programme plan that assumes the old central gate is planning against a process that no longer exists.

04

The route to market decides the shape of the work

A catalogue framework buys cloud hosting, software and support. An outcomes framework buys a team against a defined outcome, through a further competition, with no direct award. Those are different engagements with different pricing and different evidence, and choosing the route after the design has already been agreed is how a proof of concept ends up in the wrong contractual vehicle.

05

Capability has to be left behind

The Digital, Data and Technology Playbook asks for outcome-based specifications, delivery model assessments and attention to legacy and lock-in, and the AI Playbook asks that organisations have the skills to run what they adopt. A supplier whose value depends on remaining indispensable is arguing against the policy the buyer is measured on.

06

Scrutiny arrives from outside the programme

Contracts are published under the Procurement Act 2023, transparency records are public, and select committees, the National Audit Office and journalists read both. Evidence of governance is part of the deliverable rather than an internal comfort, which is exactly what we found running a portfolio office over public sector delivery at Tecknuovo.

Data residency, model risk and auditability are questions about us as much as about your estate. Our security and assurance position says what we hold today and what we do not.

If a different constraint is the one actually binding you, bring it to the call.

Talk it through
Sequencing

Where agents land first, and where they should not

Both halves matter. A supplier who only shows you the left-hand column is selling you the second year of the programme as though it were the first.

Start here

Where the value is real and the risk is contained.

  1. 1Internal knowledge retrieval across policy, guidance and procedure that is already published
  2. 2Casework preparation and triage, with the decision itself left with the caseworker
  3. 3Drafting and correspondence support, with a named human accountable for what goes out
  4. 4Portfolio and delivery reporting across a programme, the workflow behind our Tecknuovo portfolio office
  5. 5Assurance and audit evidence gathering, where the record is the product
  6. 6Developer and delivery workflow inside your own teams, where the risk surface is contained

Real constraints

The things that will bite, and worth pricing in before you sign.

  • Anything that decides or materially shapes an outcome for a citizen needs the Article 22A to 22D safeguards designed in from the first week, not added at go-live
  • Tenhaw has no agentic delivery record inside a government department, and you should weigh that against suppliers who do
  • If your organisation is in scope of the transparency standard, the record has to be producible from the running system, which is a build requirement rather than a documentation task
  • Frameworks are a route in rather than a shortcut, because an outcomes call-off runs through a further competition and no agreement here permits a direct award
  • Departmental assurance replaced the central spend control, so the approval path has to be mapped before the plan is written
  • What Tenhaw holds as a supplier, including what is certified and what is in progress, is published on the security page

Where agents land first depends on your estate. Thirty minutes is enough to sequence it.

Talk it through
Regulatory

What gates an agentic programme in government

No new AI rulebook, and no shortage of duties. What has to be published about the tool, what may be decided about a citizen without a human, the assurance departments now run themselves, and the route the work is bought through.

The Digital, Data and Technology Playbook and the routes to market

Mandated for central government departments and their arm's length bodies on a comply or explain basis, with the wider public sector expected to take it into account. It governs how digital projects are assessed, procured and delivered, which makes it the document a supplier is measured against before anyone looks at the technology.

What it requires of an agent
Eleven policies, of which four decide the shape of an agentic programme: a commercial pipeline published well ahead of the work, a delivery model assessment with a should cost model, specifications that are outcome-based rather than prescriptive, and testing and learning where a service is delivered in a new way. The routes to market carry their own shape. G-Cloud 14 (RM1557.14) is a catalogue of cloud hosting, cloud software and cloud support. Digital Outcomes and Specialists 7 (RM1043.9) went live on 30 January 2026 as an open framework under the Procurement Act 2023, in four lots covering outcomes, capability and delivery partners, specialists, and user research, and every call-off runs through a further competition.
Where programmes fall down
A supplier writes an agentic proposal against a prescriptive specification the buyer was never meant to write, or answers a specialists lot with what is really an outcomes engagement, and the mismatch surfaces in the call-off rather than in the pitch. The other pattern is a proof of concept bought through a cloud catalogue as though it were software, then found to be a services engagement when the commercial team reads the terms.
What our method does about it
We ask which route the work will be bought through before we scope it, because an outcomes lot and a specialists lot produce different teams, different pricing and different evidence. Both of our entry rungs are fixed price and time-boxed, which is the shape an outcome-based specification is asking for.

Where our evidence stops: We are not procurement advisers. Which agreement and lot you use, and whether your requirement is a covered procurement at all, are your commercial function's decisions. Ask on the call which routes to market Tenhaw can be bought through today, because the answer changes as frameworks reopen.

The AI Playbook for the UK Government

Published by the Government Digital Service on 10 February 2025, for civil servants building or buying AI and for the suppliers working with them. It updates and expands the Generative AI Framework for HMG and covers AI beyond generative models. The Digital Assurance Playbook asks assurers to check that initiatives using AI follow it.

What it requires of an agent
Ten principles. Four of them decide a build: knowing what AI is and what its limitations are, using AI lawfully, ethically and responsibly, having meaningful human control at the right stages, and working with commercial colleagues from the start. It asks that humans validate high-risk decisions influenced by AI, that products are tested before deployment, and that assurance and checks continue on the live tool rather than stopping at go-live.
Where programmes fall down
Meaningful human control is claimed and never designed. A person sits at the end of the workflow with no time, no context and no route to disagree, which is review theatre rather than control, and it is visible as such the first time anyone examines a decision. The second failure is commercial engagement arriving after the technical design, by which point the design has already decided what the contract has to say about model changes, data and exit.
What our method does about it
Human control points are named in the decision inventory before anything is built, with the information the reviewer needs at that point and a recorded route to overturn the output. We treat the Playbook's principles as acceptance criteria for the audit rather than as a document to cite in a bid, and we bring the commercial question forward because it constrains the architecture more than most technical choices do.

Where our evidence stops: Tenhaw has read the Playbook and can design to it. No department has assured a Tenhaw system against it, because we have not delivered one inside a department. Those are different claims and you should make every supplier, including us, say which one they are making.

The Algorithmic Transparency Recording Standard

Mandatory for central government departments and for arm's length bodies that deliver public services or engage directly with the public, and recommended for the wider public sector. A scope and exemptions policy published in December 2024 sets out which organisations and which algorithmic tools it is a requirement for.

What it requires of an agent
A published record of the algorithmic tool, in a complete, open, understandable and free format: what it is, why the organisation is using it, how it works, the data behind it and the human oversight around it. Because the record is public, it is the first artefact a journalist, a select committee or a claimant's solicitor will read, and it is read alongside the system rather than instead of it.
Where programmes fall down
The record is written months after go-live by someone who was not in the build, from supplier material, because nobody made those facts a delivery output. The subtler failure starts with an agentic workflow whose prompts, retrieval corpus and tool permissions change every few weeks, still described by the record written for the version that launched. That record cannot be kept true.
What our method does about it
We treat the record's fields as build outputs. The model and decision inventory the audit produces already holds purpose, data sources, models, human oversight points and named owners, which is most of what the standard asks for. Change control fires on a prompt or corpus change rather than only on a model upgrade, so the published record can be kept true rather than re-derived once a year.

Where our evidence stops: The record belongs to the organisation and publishing it is the organisation's decision. Tenhaw has never produced one on a live engagement, because we have not delivered inside an organisation in scope. What we can tell you is what the standard asks for and how to make a system emit it.

Automated decisions about citizens, under the Data (Use and Access) Act

Any controller taking significant decisions about people, which in government means most casework. Section 80 of the Data (Use and Access) Act 2025 replaced Article 22 of the UK GDPR with new Articles 22A to 22D, and the UK GDPR's other duties, including the data protection impact assessment in Article 35, apply underneath as before.

What it requires of an agent
A significant decision is one producing a legal effect for the person or a similarly significant effect. Whether it is taken solely by automated means turns on meaningful human involvement, judged including by how far the decision is reached by profiling. Where there is none, safeguards are required: information about the decision, the ability to make representations, human intervention by the controller, and the ability to contest the outcome. Special category data narrows it further, needing explicit consent or a specific legal footing before a solely automated significant decision can be taken at all.
Where programmes fall down
Human involvement is asserted rather than designed, and the assertion does not survive contact with the facts. The reviewer sees a recommendation and a score, has a handling time target, and overturns almost nothing. The other failure is a contest route that exists on paper and cannot answer the citizen's actual question, because the system kept no record of what drove the output and the retrieval corpus has moved on since.
What our method does about it
For anything touching a citizen outcome we design the human involvement so it can change the answer, which means the reviewer sees the evidence and not a score, disagreement is recorded as an outcome, and the reasons trail is retained as part of the workflow rather than in logs with a thirty day retention. We sequence citizen-facing decisioning last, after internal work, because the evidence base you will need to defend it is far cheaper to build where nobody is affected while you are learning.

Where our evidence stops: Tenhaw is not your data protection officer and gives no legal advice. Whether a decision is significant, and whether your human involvement is meaningful, are calls for your DPO and your legal advisers. We would rather have them in the design session than in the approval queue, and we have not run this design inside a department yet.

Cabinet Office spend controls, and the assurance that replaced them

Central government departments and their arm's length bodies. Most Cabinet Office spend controls ceased as a requirement on 1 April 2026, with the advertising, marketing and communications control the exception. Digital and technology assurance moved on the same date to the Digital Assurance Playbook, published by the Department for Science, Innovation and Technology.

What it requires of an agent
Organisations now design their own assurance rather than passing through a central control, with three levels of it: operational, senior management and independent review. A forward pipeline of digital and technology spend is still shared, for initiatives above £5 million whole life cost and at a £0 threshold for cryptographic products. Assurers are asked to check that initiatives using AI follow the AI Playbook for the UK Government, which is how a voluntary-sounding document becomes something your gate reviewer holds you to.
Where programmes fall down
Two mirror-image mistakes. A supplier plans a bid around a central control that no longer exists, and a buyer reads the removal of the control as the removal of the assurance. Either way the approval path is now departmental, it differs between organisations, and nobody has mapped it before the work is meant to start.
What our method does about it
We ask who approves at each stage in your organisation before we agree a plan, and we design the artefacts to be the ones your own assurance asks for rather than a separate pack produced for us. The audit's outputs, a decision inventory, an agreed autonomy boundary and an evidence trail the system emits as it runs, are close to what three levels of assurance ask for at each level, which is deliberate.

Where our evidence stops: We do not sit in your approval chain and we hold no view on your accounting officer's duties. Where an initiative needs Treasury approval, that is a business case discipline we can supply evidence into rather than one we own. We have supported assurance evidence in a supplier's portfolio office, not inside a department's own gate process.

The Procurement Act 2023 and what it publishes

Contracting authorities across the public sector, live since 24 February 2025 alongside the Procurement Regulations 2024. It applies to the agentic work as it applies to everything else, and it is the reason the engagement is a public record rather than a private arrangement.

What it requires of an agent
Notices through the commercial lifecycle: tender notices, transparency notices, contract award notices and contract change notices, with conflicts of interest identified and mitigated, rules of their own below threshold, and remedies where the rules are broken. In practice the department has to be able to say what it bought, why, and what changed, and the answer is published.
Where programmes fall down
Scope creeps from the thing that was competed into the thing that turned out to be needed. Agentic programmes do this by default, because a proof of concept that works produces an immediate request to productionise it, and productionising is usually a different requirement with a different value. Handled late, that is a contract change notice and an awkward conversation; handled at the start, it is simply the next procurement.
What our method does about it
We scope the audit and the proof of concept as separate fixed-price outcomes with their own end points, and we say at the outset that productionising is a separate decision with its own commercial route. We work that way everywhere. In a contracting authority it is the difference between a clean award and a modification nobody planned for.

Where our evidence stops: We are not procurement lawyers and we do not advise on the Act. What may be awarded, and how, belongs to your commercial and legal functions. Our contribution is not creating a modification you did not plan for, and telling you early when the work we are describing is a second procurement rather than an extension of the first.

Tenhaw builds agentic systems and the operating models around them, and works alongside the risk, compliance, legal and actuarial functions who own the interpretation of these regimes. Our security and assurance position states what we hold today and what is still in progress.

If our evidence stops short of your regime, we will say so on the call rather than after.

Talk it through
Evidence

What we have done here

Named clients where we have permission to name them, and the evidence basis stated on every one.

What our public sector evidence is, and what it is not

At Tecknuovo, a consultancy, we built a centralised portfolio management office from nothing and ran it live across 19 projects, including engagements delivering to HMRC, the MOD and Thames Water. That is delivery-transformation exposure to public sector programmes through a supplier, not agentic delivery to a department. Tecknuovo's own teams delivered those projects; our work was the office that made them visible, comparable and manageable. Nothing in that portfolio was a model, so we make no AI governance claim from it, and we have never produced an Algorithmic Transparency Recording Standard record on a live engagement. If you need a supplier who has already taken an agentic system through a department's own assurance, we are not it yet.

Ask for the detail behind any of these on the call.

Talk it through
The patterns behind this

How this work is actually built

The guides carrying the patterns this sector buys first. Each states its own evidence basis at the top: what we have delivered, and what is method rather than a build.

If one of these patterns is the shape of your problem, bring it to the call.

Talk it through
book a call

Thirty minutes on Public Sector and Government, with James Rooney

We'll be specific about what applies in your sector and what does not, and you'll leave with a rough scope whether you engage us or not.

most start with a fixed-price AI Readiness Audit · £44,000 · 4 weeks · working prototypes

// pick a slot · cal.com/tenhaw/professional-servicesLIVE CALENDAR

Calendar not loading? Open it on cal.com or email hello@tenhaw.com.

Public Sector and Government: your questions

Does Tenhaw work with the public sector?

Yes. Tenhaw was Tecknuovo's portfolio manager, hands on under the contract, and in that role built a centralised portfolio management office from nothing over nine months and ran it live across 19 projects, including public sector delivery for HMRC, the MOD and Thames Water, while coaching the junior delivery leads who took it over. Tecknuovo's own teams delivered those projects; the office is what made them visible, comparable and manageable, and it reinforced their credibility on exactly that work. Alongside it sits the agentic evidence, a two-week London specialty insurance proof of concept taking PDFs to business intelligence on Azure, now being productionised in month three.

What does the Algorithmic Transparency Recording Standard require of an AI supplier?

Strictly, nothing. The standard binds the organisation, not the supplier, though in practice it decides what a supplier has to produce. The standard is mandatory for central government departments and for arm's length bodies that deliver public services or engage directly with the public, and it asks for a published record of what the algorithmic tool is, why the organisation is using it, how it works, the data behind it and the human oversight around it. That means the facts have to exist inside delivery: purpose, data sources, models and versions, human oversight points and named owners, all current rather than as at launch. The test is simple. Ask whether their build produces those fields as outputs, and what happens to the published record when a prompt or a retrieval corpus changes next month.

Can a government department let an AI agent decide a case?

It depends on whether the decision is significant and whether a human is meaningfully involved. Section 80 of the Data (Use and Access) Act 2025 replaced Article 22 of the UK GDPR with Articles 22A to 22D. A significant decision is one with a legal effect or a similarly significant effect on the person, and whether it counts as solely automated turns on meaningful human involvement, judged including by how far the decision is reached through profiling. Where there is no meaningful human involvement, safeguards are required: information about the decision, the ability to make representations, human intervention by the controller and the ability to contest the outcome. Special category data narrows it further, needing explicit consent or a specific legal footing. The design consequence is that a caseworker with a recommendation, a score and a handling time target is probably not meaningful involvement, so the reviewer has to see the evidence, be able to disagree, and have that disagreement recorded. Tenhaw is not your DPO and this is not legal advice.

How is agentic AI bought in UK government?

Through the same routes as other digital work, and the route shapes the engagement. G-Cloud 14 (RM1557.14) is a catalogue for cloud hosting, cloud software and cloud support. Digital Outcomes and Specialists 7 (RM1043.9) went live on 30 January 2026 as an open framework under the Procurement Act 2023, with four lots covering digital outcomes, capability and delivery partners, specialists, and user research, and it requires a further competition rather than a direct award. Both are run by the Government Commercial Agency, which Crown Commercial Service became on 1 April 2026. Over the top sits the Digital, Data and Technology Playbook, which asks for outcome-based specifications and a delivery model assessment on a comply or explain basis. The practical advice is to settle the route before the design, because an outcomes lot and a specialists lot produce different teams, different pricing and different evidence.

Did Cabinet Office spend controls end, and what replaced them for AI projects?

Most Cabinet Office spend controls ceased as a requirement on 1 April 2026, with the advertising, marketing and communications control the exception. Digital and technology assurance did not end with them. It moved to the Digital Assurance Playbook, published by the Department for Science, Innovation and Technology on the same date. Under it, organisations design their own assurance across three levels: operational, senior management and independent review. They still share a forward pipeline of digital and technology spend above £5 million whole life cost, with a £0 threshold for cryptographic products. For AI specifically, assurers are asked to check that the initiative follows the AI Playbook for the UK Government. So the gate is now inside your organisation rather than in the centre, it is not identical between departments, and a delivery plan that has not mapped it is planning against a process that no longer exists.

What should a department ask an agentic AI supplier to evidence?

Five things, all of which should exist before a contract is signed. Which decisions the agent may take and which need a human, written down as an inventory rather than described in a workshop. Where the human sits, what they see, and how their disagreement is recorded, because meaningful human involvement is a design property and not a claim. How the transparency record will be produced and kept true when prompts, corpora and model versions change. What the system emits as evidence while it runs, rather than what can be reconstructed from logs afterwards. And who owns the prompts, evaluation sets and retrieval corpora on exit. Ask every supplier, us included, to show those five as artefacts from delivered work.

Has Tenhaw delivered an AI system inside a government department?

Our government record is portfolio delivery. Tenhaw was Tecknuovo's portfolio manager, hands on under the contract, standing up a portfolio management office from nothing and running it live across 19 projects, including delivery for HMRC, the MOD and Thames Water, where the governance record had to stay current as the work ran rather than be assembled afterwards. The agentic builds so far sit in other sectors. A two-week London specialty insurance proof of concept took PDFs to business intelligence on Azure, pair-programmed with the client's own engineer and now being productionised in month three, and more than twenty agentic products have come through Velocity84, Tenhaw's build lab.

Is the AI Playbook for the UK Government mandatory?

In practice yes, even though it reads as guidance rather than law. The Government Digital Service published the Playbook on 10 February 2025, updating the Generative AI Framework for HMG, with ten principles for civil servants building or buying AI. Since assurance moved inside departments on 1 April 2026, the Digital Assurance Playbook asks assurers to check that initiatives using AI follow it, so your gate reviewer applies it. Four principles decide a build: knowing what AI is and what its limitations are, using it lawfully, ethically and responsibly, meaningful human control at the right stages, and working with commercial colleagues from the start. We treat those as acceptance criteria, not lines to cite in a bid.

What can a department automate before touching casework decisions?

Plenty, and the order matters more than the ambition. The workflows worth taking first are internal: knowledge retrieval across policy, guidance and procedure you already publish, casework preparation and triage with the decision itself left with the caseworker, drafting and correspondence with a named human accountable for what goes out, portfolio and delivery reporting across a programme, assurance and audit evidence gathering where the record is the product, and developer workflow inside your own teams, where the risk surface is contained. None of those decides a citizen's outcome. We sequence citizen-facing decisioning last because the evidence base you will need to defend it is far cheaper to build where nobody is affected while you are learning.

Can a department extend an AI proof of concept into a production contract?

Treat production as a separate procurement, not an extension. A proof of concept that works produces an immediate request to productionise it, usually a different requirement at a different value, which is how agentic programmes creep by default. Under the Procurement Act 2023 what was bought, why, and what changed get published. Handled late it is a contract change notice nobody planned for; handled at the start it is simply the next procurement. We scope the proof of concept as a fixed-price outcome with its own end point, £20k–£55k over two to four weeks, and say up front that productionising is a separate decision with its own route. What may be awarded, and how, is your commercial function's call.

What actually slows down public sector AI transformation in the UK?

Not the technology. Public sector AI transformation in the UK is gated by three published duties that already exist: what an organisation has to record in public about an algorithmic tool, what may be decided about a citizen without meaningful human involvement, and how the work is bought. The AI Playbook for the UK Government sits over the top, and since 1 April 2026 digital and technology assurance runs inside your own organisation rather than through a central Cabinet Office control. Programmes stall when none of that is settled before the build is scoped, and the approval path is not the same in any two departments. Settle it first and the build is the straightforward part.

What happens when the NAO or a select committee asks about our AI system?

They read the published record before anyone talks to you. Contracts are published under the Procurement Act 2023 and transparency records are public, and select committees, the National Audit Office and journalists read both, so evidence of governance is part of the deliverable rather than an internal comfort. The practical test is whether the system produces that evidence while it runs: purpose, data sources, models, human oversight points and named owners, current rather than as at launch. That is what we found running a portfolio office over public sector delivery at Tecknuovo, where the record had to exist as the work ran rather than be assembled afterwards from a sales deck.

Do we need a delivery model assessment for an agentic AI project?

For a central government department or arm's length body, yes, on a comply or explain basis. The Digital, Data and Technology Playbook carries eleven policies, four of which shape an agentic programme: a commercial pipeline published well ahead of the work, a delivery model assessment with a should cost model behind it, specifications that are outcome-based rather than prescriptive, and testing and learning where a service is delivered in a new way. The awkward part is costing a delivery model before anyone knows what the agents will do, which is why both of our entry rungs are fixed price and time-boxed, £44,000 over four weeks for the audit and £20k–£55k over two to four weeks for a proof of concept.

When should commercial and legal join a government AI project?

Before the technical design, not after it. Working with commercial colleagues from the start is one of the AI Playbook's ten principles, and the usual failure is commercial arriving late, by which point the design has already decided what the contract has to say about model changes, data and exit. Your data protection officer and legal advisers come in at the same point on anything touching a citizen. We would rather have them in the design session than in the approval queue. Add whoever approves at each of your three assurance levels, operational, senior management and independent review, because the approval path is departmental now and differs between organisations.

What if a citizen challenges a decision our agent helped make?

You have to be able to say what drove the output on the day, months after the day. Articles 22A to 22D give the person information about the decision, the ability to make representations, human intervention by the controller and the ability to contest the outcome. The failure we design against is a contest route that exists on paper and cannot answer the citizen's question, because nothing kept a record of what drove the output and the retrieval corpus has moved on. So the reasons trail is retained inside the workflow rather than in logs on thirty day retention, and a reviewer's disagreement is recorded as an outcome. Whether a decision is significant is a call for your DPO.

Will an AI readiness audit produce evidence our assurance gate accepts?

That is what it is designed for. Since 1 April 2026 organisations design their own assurance across three levels, operational, senior management and independent review, and assurers are asked to check that AI initiatives follow the AI Playbook. The audit is £44,000 fixed over four weeks and ends in working prototypes. Its other outputs are a decision inventory holding purpose, data sources, models, human oversight points and named owners, an agreed autonomy boundary, and an evidence trail the system emits as it runs. Those map closely to what each level of assurance asks for, deliberately. We do not sit in your approval chain, so we ask who approves at each stage before agreeing a plan.

Do your people hold security clearance for government work?

Everyone with client access is BS7858 screened before they touch anything, Cyber Essentials Plus is in progress and ISO 27001 is targeted for 2027, all published on the security page. Vetted SC or DV clearance is not on that list, so settle that before scoping rather than during delivery. Where the work does not need it, we deploy on your infrastructure under your policies as usual, with UK data residency by default and the EU available, and the team is two or three senior people with James Rooney leading the engagement personally.

Do the UK government AI rules apply to councils too?

It splits, so check before anyone quotes a duty at you. The Algorithmic Transparency Recording Standard is mandatory for central government departments and for arm's length bodies that deliver public services or engage directly with the public, recommended for the wider public sector, with a scope and exemptions policy published in December 2024. The Digital, Data and Technology Playbook binds central departments and their arm's length bodies on a comply or explain basis, with the wider public sector expected to take it into account. Two duties do not split. Articles 22A to 22D reach any controller taking significant decisions about people, and the Procurement Act 2023 applies to contracting authorities across the public sector.