Agentic transformation in Retail, Consumer and Media
Where agentic returns are largest and adoption windows are shortest.
named retail, consumer and media clients, with two more as roles held
3
the Discovery+ launch, under a fixed CEO deadline, across six teams
On time
to a predictable app and integration capability at Greggs
6 months
Work delivered atGreggs·YOOX NET-A-PORTER·Colart
Roles held inside: Sky, Discovery. Delivery and transformation roles, on contract and in permanent positions, rather than engagements delivered under the Tenhaw banner.
Retail, consumer and media organisations see the fastest agentic returns because volume is high, feedback loops are short and decisions are frequently reversible, but they also have the least tolerance for a transformation that takes eighteen months to show results. The regulatory floor is lower than in financial services, and it is not absent. Since 6 April 2025 the CMA has enforced consumer protection law directly under the DMCC Act, which puts anything an agent writes for a customer squarely inside the unfair commercial practices rules, and UK GDPR governs the personalisation data underneath it. Tenhaw has run delivery transformation at Greggs, YOOX NET-A-PORTER and Colart, and its founder held delivery roles at Sky and Discovery+. Tenhaw is a UK agentic AI consultancy and delivery partner, and sequences programmes so something is in production inside a peak-trading cycle rather than after it.
That is the short answer for the sector. The call is where it gets specific to your organisation.
Not the ones that sound good in a deck. These determine which workflows can move to agents at all, and in what order.
01
The trading calendar does not negotiate
Peak trading freezes change for a quarter of the year. An agentic programme that ignores the calendar loses a third of its delivery window, and sequencing around it is a design constraint rather than a scheduling detail.
02
Margin pressure makes the case, and limits the budget
The commercial case for agents is strongest where margins are thinnest, which is also where the appetite for multi-year consultancy spend is lowest. Engagements have to show return inside a trading cycle.
03
Customer experience risk is immediate and public
An agent that gets a customer interaction wrong in retail generates a social media incident the same afternoon. The human-in-the-loop boundary sits differently here than in back-office work.
04
Frontline and head office are different transformations
Head office knowledge work and store or contact-centre operations have almost nothing in common in adoption terms. Treating them as one programme is a reliable way to fail at both.
Data residency, model risk and auditability are questions about us as much as about your estate. Our security and assurance position says what we hold today and what we do not.
If a different constraint is the one actually binding you, bring it to the call.
The rules that reach anything an agent writes for a customer
Lighter than in financial services. Consumer law, data protection and rights in generated content are where retail and media programmes get caught, usually by removing the human who used to catch it.
UK consumer law and the CMA
Any business selling to UK consumers. The unfair commercial practices rules in the Digital Markets, Competition and Consumers Act apply to practices from 6 April 2025, and the CMA now decides for itself whether consumer law has been infringed rather than litigating first, with penalties of up to 10% of global turnover, or £300,000 if that is greater, and the power to direct redress to consumers.
What it requires of an agent
The unfair commercial practices rules do not care who wrote the words. Product information must not mislead by action or by omission. The total price including mandatory fees has to be presented up front rather than assembled during checkout. Fake or incentivised reviews presented as genuine are a banned practice, with a duty to take reasonable steps to stop them appearing. Anything an agent generates that reaches a customer is a commercial practice by the trader, and the trader owns it.
Where programmes fall down
A description-generation agent infers an attribute the product does not have. It reads fluently, it is plausible, and it is a misleading action. Review summarisation blends incentivised reviews into an average nobody can defend. A promotion or pricing agent produces a display that separates a mandatory fee from the headline price. In every case the control that would have caught it, a person reading the output before it shipped, is exactly the control the automation removed.
What our method does about it
Any generated output making a factual claim about a product is grounded in a field in a system of record, and anything the model asserts that cannot be matched to one is held for a human, not published. We test the claim path rather than the tone, because tone is what everyone reviews and claims are what gets enforced. Pricing and promotion agents sit behind a rules layer they cannot talk their way around.
Where our evidence stops: We are not consumer law advisers, and the line between acceptable puffery and a misleading claim is a judgement your legal team makes. What we build is the mechanism that lets them make it once and have it hold at volume.
Any organisation processing UK personal data. The Data (Use and Access) Act 2025 reworked parts of the regime, notably around automated decision-making, and it is the ICO's guidance rather than the headlines that a DPO will hold a programme to.
What it requires of an agent
A lawful basis, and a purpose the data was actually collected for, which is where retail personalisation gets uncomfortable, because data gathered to fulfil an order was not obviously collected to train a recommendation model. A DPIA where processing is likely to be high risk. Data minimisation, which sits awkwardly against a retrieval corpus that is far easier to build by copying everything. And for decisions about people with significant effect, safeguards including meaningful human intervention and a route to contest the outcome.
Where programmes fall down
The DPIA is done once for the pilot and never revisited when autonomy widens, which is the change that actually mattered. Customer records leak into a retrieval corpus with no retention rule, so deletion requests are honoured in the database and not in the index. And nobody builds the contest path, so the first customer who challenges a decision reaches a person who cannot see how it was reached.
What our method does about it
Purpose and lawful basis are inputs to the design rather than a gate at the end. Retrieval corpora get retention and deletion behaviour built in from the start. We re-ask the DPIA question whenever autonomy changes, not only at go-live. And our default in pilots is synthetic or mocked data, which takes the hardest approval out of the fastest-moving phase of the work.
Where our evidence stops: Tenhaw is not your DPO and gives no legal advice on data protection. We work to what your DPO decides, and we would rather have them in the design session than in the approval queue.
Media and content businesses, and any retailer producing creative assets at volume. Copyright and contractual rights in generated output, and, for anything with user-to-user features, the Online Safety Act duties that Ofcom enforces.
What it requires of an agent
Rights have to be traceable. UK law still has no broad commercial text-and-data-mining exception, and the question has now been asked and left open. The government's copyright and AI report of 18 March 2026 says a broad exception with an opt-out is no longer its preferred way forward and that it will gather further evidence. So your position rests on supplier terms, the licences behind the training data and the warranties you can actually negotiate. Talent, likeness and music rights are contractual and specific. Platform duties, where they apply, expect risk assessment and proportionate systems rather than reactive takedown.
Where programmes fall down
An asset generated by a tool whose terms do not clearly assign output rights ends up in a paid campaign, and the question arrives eighteen months later when nobody remembers which tool made it or from what. That is a provenance failure before it is a legal one, and provenance is the part you can engineer.
What our method does about it
Provenance is recorded at the moment of generation: which tool, which version, which inputs, which licence, retained with the asset. Supplier terms get read before the pilot rather than before the campaign. It is unglamorous, and it is the difference between a rights query taking an hour and taking a month.
Where our evidence stops: We do not clear rights and we do not advise on copyright. This is an engineering discipline that makes your rights and legal teams' work possible at volume, and it does not replace them.
Tenhaw builds agentic systems and the operating models around them, and works alongside the risk, compliance, legal and actuarial functions who own the interpretation of these regimes. Our security and assurance position states what we hold today and what is still in progress.
If our evidence stops short of your regime, we will say so on the call rather than after.
The guides carrying the patterns this sector buys first. Each states its own evidence basis at the top: what we have delivered, and what is method rather than a build.
Where do retailers get the fastest return from AI agents?
In high-volume, reversible-decision workflows: merchandising and demand signals, supply chain exception handling, customer service triage with human resolution, and content production at volume. These have short feedback loops, contained risk, and produce measurable results inside a single trading cycle.
Does UK consumer law apply to product descriptions written by AI?
Yes. The unfair commercial practices rules apply to the trader, not to the author, so a misleading description is a misleading description whether a copywriter or a model produced it. The rules in the Digital Markets, Competition and Consumers Act apply to practices from 6 April 2025, and the CMA can now decide for itself that they have been broken rather than going to court first, with penalties of up to 10% of global turnover and the power to direct redress. The practical design response is to ground every factual claim about a product in a field in a system of record, and to hold anything the model asserts that cannot be matched to one. The same logic covers price display, where mandatory fees have to appear in the total up front, and reviews, where presenting incentivised reviews as genuine is a banned practice.
Do we need a DPIA for an AI agent that uses customer data?
Almost always, and you need it more than once. A DPIA is required where processing is likely to result in high risk, which covers most personalisation, profiling and large-scale use of customer data. The failure we see is not a missing DPIA, it is one completed for a narrow pilot and never revisited when autonomy widened, which is the change that altered the risk. Two other things get missed. A retrieval corpus needs its own retention and deletion behaviour, because honouring a deletion request in the database and not in the index is not honouring it. And a decision with significant effect on a person needs a real route to human intervention and to contest the outcome. Tenhaw is not your DPO and gives no legal advice here.
Who owns the rights to content generated by an AI model?
It depends on the tool's terms, the licences behind its training data and the warranties you were able to negotiate. UK law still has no broad commercial text-and-data-mining exception to fall back on, and the government's copyright and AI report of 18 March 2026 dropped a broad exception with an opt-out as its preferred approach, saying it would gather further evidence instead. The engineering answer is more useful than the legal one, so record provenance at the moment of generation, which tool, which version, which inputs, which licence, and keep it with the asset. Most rights problems in media are discovered eighteen months later, and the difference between an hour of work and a month of work is whether anyone can say where the asset came from.
How do you run an AI programme around peak trading?
By treating the change freeze as a design constraint from the start. Delivery is sequenced so that pilots ship and stabilise before freeze, the freeze period is used for adoption, measurement and operating-model work that requires no deployment, and the next build window is planned against the trading calendar rather than a generic quarterly plan.
What is different about frontline versus head office AI adoption?
Almost everything. Head office knowledge workers adopt tools that make their own work easier and have discretion over how they work. Frontline staff work to fixed processes, often on shared devices, with little discretion and immediate customer pressure. The two require separate adoption designs, separate measurement, and usually separate sequencing.
Can we use AI to summarise customer reviews?
Yes, and the control that matters is knowing which reviews fed the summary. Presenting fake or incentivised reviews as genuine is a banned practice under the unfair commercial practices rules, and the trader carries a duty to take reasonable steps to stop them appearing, so a summariser that quietly folds incentivised reviews into a headline average produces a number nobody can defend. Build it so every claim the summary makes traces back to reviews you can identify, and hold anything the model asserts that the underlying reviews do not support. We test the claim path rather than the tone. Where puffery ends and a misleading claim begins is your legal team's call, not ours.
Can we let an AI agent run pricing and promotions on its own?
Only behind a rules layer it cannot talk its way around. The total price including mandatory fees has to be presented up front rather than assembled during checkout. Price display is regulated in its own right, so a promotion agent that splits a mandatory fee off the headline price has produced a misleading practice on the trader's behalf. Since 6 April 2025 the CMA decides for itself whether consumer law has been infringed rather than litigating first, with penalties of up to 10% of global turnover, or £300,000 if that is greater, and the power to direct redress. Put the pricing rules in code the agent cannot override, and test what the display claims rather than how it reads.
Can we use past order data to train a recommendation model?
Not automatically. UK GDPR asks for a lawful basis and a purpose the data was actually collected for, and data gathered to fulfil an order was not obviously collected to train a recommendation model, which is where retail personalisation gets uncomfortable. That does not make it impossible, it makes purpose and lawful basis inputs to the design rather than a gate at the end. The Data (Use and Access) Act 2025 reworked parts of the regime, and it is the ICO's guidance rather than the headlines that a DPO holds a programme to. Our default in pilots is synthetic or mocked data, which takes the hardest approval out of the fastest-moving phase. We work to what your DPO decides.
Which retailers and media brands has Tenhaw worked with?
On the retail side, under the Tenhaw banner: five agile teams coordinated through YOOX NET-A-PORTER's £1bn e-commerce re-platform, the mobile app and integration squads at Greggs made predictable and trusted again with data showing that clearing tech debt sped delivery up, and three newly merged teams at Colart turned into one unit that shipped an e-commerce site. On the media side, James Rooney ran the visual rebrand team on the Discovery+ and Eurosport launch, six teams against a date the CEO had already announced, and held delivery roles at Sky. That work was delivery transformation rather than agentic build, and we label it that way because the two are not the same claim.
What does a retail AI operating model look like in practice?
A retail AI operating model comes down to four choices: which workflows agents touch, where the human sits in each one, how the build is sequenced against the trading calendar, and who owns what an agent says to a customer. The last one is the trap. Anything an agent generates that reaches a customer is a commercial practice by the trader, so the claim path belongs in the design rather than in a review at the end. The other structural point is that head office and store or contact-centre operations are two different transformations, and running them as one programme is a reliable way to fail at both. Peak freezes make sequencing a design constraint, not a scheduling detail.
Why do AI demand forecasts go wrong around promotions?
Because seasonal and promotional data makes naive forecasting agents unreliable, and retail history is mostly seasons and promotions. The model reads a promotional spike as demand rather than as a lever somebody pulled, then carries that shape into a week when nobody is pulling it. The version that works feeds the promotional calendar and price changes in as explicit inputs instead of leaving the agent to infer them, and keeps a buyer between the recommendation and the purchase order. Merchandising and demand signals are still one of the fastest places in retail to get a return, because the decisions are frequent and reversible. What fails is giving the forecast to an agent and the promotional calendar to nobody.
Can agents take on supply chain exception handling?
Yes, and it is one of the first places we would look, because that is variance humans currently absorb by hand and the volume is high enough to show a result inside one trading cycle. Every time, the agent assembles the exception, a late shipment, a short delivery, a substitution, pulls the related records and the history, proposes a resolution and hands a person a decision instead of a search. Two boundaries hold. It does not commit money or change a customer's order on its own, and anything it produces that reaches the customer, a revised delivery promise included, is a commercial practice by the trader and needs grounding in a system of record.
How do you stop a customer-facing agent becoming a PR incident?
By putting the boundary in a different place from where you would put it in the back office. Get a customer interaction wrong in retail and it is a social media post the same afternoon, which is a different risk profile from mislabelling an invoice, so the agent drafts and a person resolves rather than the other way round. Start where a mistake is recoverable: triage, summarisation, routing, and internal drafting that a colleague sends. Widen autonomy only where the evidence from the narrow version supports it. The failure mode is rarely a rude reply. It is a confident factual assertion about a product, a price or a delivery date that nobody checked.
How do retailers justify AI spend when margins are thin?
By buying it in pieces small enough to prove themselves inside a trading cycle. The commercial case for agents is strongest where margins are thinnest, which is also where the appetite for multi-year consultancy spend is lowest, so the shape of the spend has to match. An agentic proof of concept is £20k–£55k fixed over 2–4 weeks. The AI readiness audit is £44,000 fixed over four weeks and ends in working prototypes, and a recommendation to stop is a valid outcome. After that, engagements are retainer-shaped rather than milestone-shaped, and a month that delivers no measurable value gets reported as a failed month. That is the honest version of return inside a trading cycle.
Can AI take over the manual reporting from stores and field teams?
Yes, and it is usually the least contentious place to start, because what gets replaced is manual consolidation rather than judgement. Store and field reporting in most retailers is someone pulling figures out of several systems by hand every week, which is high volume, low risk and easy to check, because the numbers already exist to reconcile against. The design work is not the model. It is deciding what the report is for, cutting the fields nobody acts on, and giving the frontline something back rather than only feeding head office. Adoption is the risk here rather than the build. A store team will use a report that saves them an evening and ignore one written for head office.
Is agentic AI in retail an IT project or a trading one?
A trading one with engineering inside it. If IT owns it, you get something merchandising did not ask for, store operations cannot use, and a frontline half of the programme that quietly never happens. The sponsor should be whoever owns the trading outcome, with the merchandising or category lead, whoever runs stores or the contact centre, brand or legal for the line between puffery and a misleading claim, and your DPO in the design sessions rather than in the approval queue. Engineering reports into that group instead of running alongside it. If nobody in the room can approve a change to a customer-facing message, the wrong people are in the room.
Does the Online Safety Act apply to AI features in our app?
Yes, if the app has user-to-user features, and the duties Ofcom enforces do not change because a model wrote the content. Reviews, comments, community feeds and anything an agent generates or promotes into them are part of the system being assessed, so putting an agent on that surface belongs in the assessment before it ships rather than after. The duties expect proportionate systems rather than reactive takedown, which is an argument for emitting the evidence trail as the system runs instead of reconstructing it later. Where an agent supports that work the customer-facing boundary still holds, so it can gather and prioritise while a person owns any decision that lands on someone. We build the mechanism, not the legal position.