Sector · Retail, Consumer and Media

Agentic transformation in Retail, Consumer and Media

Where agentic returns are largest and adoption windows are shortest.

named retail, consumer and media clients
7
the Discovery+ launch, under a fixed CEO deadline, across six teams
On time
to a predictable app and integration capability at Greggs
6 months
Work delivered at
GreggsSkyDiscoveryYOOX NET-A-PORTERColartand 1 more

The short answer

Retail, consumer and media organisations see the fastest agentic returns because volume is high, feedback loops are short and decisions are frequently reversible, but they also have the least tolerance for a transformation that takes eighteen months to show results. The regulatory floor is lower than in financial services, and it is not absent. Since 6 April 2025 the CMA has enforced consumer protection law directly under the DMCC Act, which puts anything an agent writes for a customer squarely inside the unfair commercial practices rules, and UK GDPR governs the personalisation data underneath it. Tenhaw has run delivery transformation at Greggs, Sky, Discovery+, YOOX NET-A-PORTER and Colart, and sequences agentic programmes so something is in production inside a peak-trading cycle rather than after it.

Regulation in retail, consumer and media

The constraints that decide the sequence

Not the ones that sound good in a deck. These determine which workflows can move to agents at all, and in what order.

01

The trading calendar does not negotiate

Peak trading freezes change for a quarter of the year. An agentic programme that ignores the calendar loses a third of its delivery window, and sequencing around it is a design constraint rather than a scheduling detail.

02

Margin pressure makes the case, and limits the budget

The commercial case for agents is strongest where margins are thinnest, which is also where the appetite for multi-year consultancy spend is lowest. Engagements have to show return inside a trading cycle.

03

Customer experience risk is immediate and public

An agent that gets a customer interaction wrong in retail generates a social media incident the same afternoon. The human-in-the-loop boundary sits differently here than in back-office work.

04

Frontline and head office are different transformations

Head office knowledge work and store or contact-centre operations have almost nothing in common in adoption terms. Treating them as one programme is a reliable way to fail at both.

Data residency, model risk and auditability are questions about us as much as about your estate. Our security and assurance position says what we hold today and what we do not.

Sequencing

Where agents land first, and where they should not

Both halves matter. A supplier who only shows you the left-hand column is selling you the second year of the programme as though it were the first.

Start here

Where the value is real and the risk is contained.

  1. 1Merchandising and demand signals, where decisions are frequent and reversible
  2. 2Content and asset production at volume, particularly in media
  3. 3Customer service triage and summarisation with human resolution
  4. 4Supply chain exception handling, where humans currently absorb the variance
  5. 5Store and field operations reporting, replacing manual consolidation

Real constraints

The things that will bite, and worth pricing in before you sign.

  • Peak trading freezes remove roughly a quarter of the delivery year
  • Customer-facing agents need a tighter human-in-the-loop boundary than back office
  • Frontline adoption requires different design entirely from head-office adoption
  • Seasonal and promotional data makes naive forecasting agents unreliable
  • Anything an agent writes for a customer is a commercial practice by the trader, and the CMA can now enforce that directly
Regulatory

The rules that reach anything an agent writes for a customer

Lighter than in financial services. Consumer law, data protection and rights in generated content are where retail and media programmes get caught, usually by removing the human who used to catch it.

UK consumer law and the CMA

Any business selling to UK consumers. The unfair commercial practices rules in the Digital Markets, Competition and Consumers Act apply to practices from 6 April 2025, and the CMA now decides for itself whether consumer law has been infringed rather than litigating first, with penalties of up to 10% of global turnover, or £300,000 if that is greater, and the power to direct redress to consumers.

What it requires of an agent
The unfair commercial practices rules do not care who wrote the words. Product information must not mislead by action or by omission. The total price including mandatory fees has to be presented up front rather than assembled during checkout. Fake or incentivised reviews presented as genuine are a banned practice, with a duty to take reasonable steps to stop them appearing. Anything an agent generates that reaches a customer is a commercial practice by the trader, and the trader owns it.
Where programmes fall down
A description-generation agent infers an attribute the product does not have. It reads fluently, it is plausible, and it is a misleading action. Review summarisation blends incentivised reviews into an average nobody can defend. A promotion or pricing agent produces a display that separates a mandatory fee from the headline price. In every case the control that would have caught it, a person reading the output before it shipped, is exactly the control the automation removed.
What our method does about it
Any generated output making a factual claim about a product is grounded in a field in a system of record, and anything the model asserts that cannot be matched to one is held for a human, not published. We test the claim path rather than the tone, because tone is what everyone reviews and claims are what gets enforced. Pricing and promotion agents sit behind a rules layer they cannot talk their way around.

Where our evidence stops: We are not consumer law advisers, and the line between acceptable puffery and a misleading claim is a judgement your legal team makes. What we build is the mechanism that lets them make it once and have it hold at volume.

UK GDPR, the ICO and personalisation data

Any organisation processing UK personal data. The Data (Use and Access) Act 2025 reworked parts of the regime, notably around automated decision-making, and it is the ICO's guidance rather than the headlines that a DPO will hold a programme to.

What it requires of an agent
A lawful basis, and a purpose the data was actually collected for, which is where retail personalisation gets uncomfortable: data gathered to fulfil an order was not obviously collected to train a recommendation model. A DPIA where processing is likely to be high risk. Data minimisation, which sits awkwardly against a retrieval corpus that is far easier to build by copying everything. And for decisions about people with significant effect, safeguards including meaningful human intervention and a route to contest the outcome.
Where programmes fall down
The DPIA is done once for the pilot and never revisited when autonomy widens, which is the change that actually mattered. Customer records leak into a retrieval corpus with no retention rule, so deletion requests are honoured in the database and not in the index. And nobody builds the contest path, so the first customer who challenges a decision reaches a person who cannot see how it was reached.
What our method does about it
Purpose and lawful basis are inputs to the design rather than a gate at the end. Retrieval corpora get retention and deletion behaviour built in from the start. We re-ask the DPIA question whenever autonomy changes, not only at go-live. And our default in pilots is synthetic or mocked data, which takes the hardest approval out of the fastest-moving phase of the work.

Where our evidence stops: Tenhaw is not your DPO and gives no legal advice on data protection. We work to what your DPO decides, and we would rather have them in the design session than in the approval queue.

Rights, provenance and platform duties in media

Media and content businesses, and any retailer producing creative assets at volume. Copyright and contractual rights in generated output, and, for anything with user-to-user features, the Online Safety Act duties that Ofcom enforces.

What it requires of an agent
Rights have to be traceable. UK law still has no broad commercial text-and-data-mining exception, and the question has now been asked and left open: the government's copyright and AI report of 18 March 2026 says a broad exception with an opt-out is no longer its preferred way forward and that it will gather further evidence. So your position rests on supplier terms, the licences behind the training data and the warranties you can actually negotiate. Talent, likeness and music rights are contractual and specific. Platform duties, where they apply, expect risk assessment and proportionate systems rather than reactive takedown.
Where programmes fall down
An asset generated by a tool whose terms do not clearly assign output rights ends up in a paid campaign, and the question arrives eighteen months later when nobody remembers which tool made it or from what. That is a provenance failure before it is a legal one, and provenance is the part you can engineer.
What our method does about it
Provenance is recorded at the moment of generation: which tool, which version, which inputs, which licence, retained with the asset. Supplier terms get read before the pilot rather than before the campaign. It is unglamorous, and it is the difference between a rights query taking an hour and taking a month.

Where our evidence stops: We do not clear rights and we do not advise on copyright. This is an engineering discipline that makes your rights and legal teams' work possible at volume, and it does not replace them.

Tenhaw builds agentic systems and the operating models around them, and works alongside the risk, compliance, legal and actuarial functions who own the interpretation of these regimes. Our security and assurance position states what we hold today and what is still in progress.

Retail, Consumer and Media: your questions

Where do retailers get the fastest return from AI agents?

In high-volume, reversible-decision workflows: merchandising and demand signals, supply chain exception handling, customer service triage with human resolution, and content production at volume. These have short feedback loops, contained risk, and produce measurable results inside a single trading cycle.

Does UK consumer law apply to product descriptions written by AI?

Yes. The unfair commercial practices rules apply to the trader, not to the author, so a misleading description is a misleading description whether a copywriter or a model produced it. The rules in the Digital Markets, Competition and Consumers Act apply to practices from 6 April 2025, and the CMA can now decide for itself that they have been broken rather than going to court first, with penalties of up to 10% of global turnover and the power to direct redress. The practical design response is to ground every factual claim about a product in a field in a system of record, and to hold anything the model asserts that cannot be matched to one. The same logic covers price display, where mandatory fees have to appear in the total up front, and reviews, where presenting incentivised reviews as genuine is a banned practice.

Do we need a DPIA for an AI agent that uses customer data?

Almost always, and more importantly you need it more than once. A DPIA is required where processing is likely to result in high risk, which covers most personalisation, profiling and large-scale use of customer data. The failure we see is not a missing DPIA, it is a DPIA completed for a narrow pilot and never revisited when the agent's autonomy widened, which is the change that altered the risk. Two other things tend to get missed: a retrieval corpus needs its own retention and deletion behaviour, because honouring a deletion request in the database and not in the index is not honouring it, and a decision with significant effect on a person needs a real route to human intervention and to contest the outcome. Tenhaw is not your DPO and does not give legal advice here.

Who owns the rights to content generated by an AI model?

It depends on the tool's terms, the licences behind its training data and the warranties you were able to negotiate, and UK law still has no broad commercial text-and-data-mining exception to fall back on: the government's copyright and AI report of 18 March 2026 dropped a broad exception with an opt-out as its preferred approach and said it would gather further evidence instead. The engineering answer is more useful than the legal one: record provenance at the moment of generation, which tool, which version, which inputs, which licence, and keep it with the asset. Most rights problems in media are discovered eighteen months later, and the difference between an hour of work and a month of work is whether anyone can say where the asset came from.

How do you run an AI programme around peak trading?

By treating the change freeze as a design constraint from the start. Delivery is sequenced so that pilots ship and stabilise before freeze, the freeze period is used for adoption, measurement and operating-model work that requires no deployment, and the next build window is planned against the trading calendar rather than a generic quarterly plan.

What is different about frontline versus head office AI adoption?

Almost everything. Head office knowledge workers adopt tools that make their own work easier and have discretion over how they work. Frontline staff work to fixed processes, often on shared devices, with little discretion and immediate customer pressure. The two require separate adoption designs, separate measurement, and usually separate sequencing.

Thirty minutes on Retail, Consumer and Media, with James Rooney

We'll be specific about what applies in your sector and what does not, and you'll leave with a rough scope whether you engage us or not.

30 minutesWith James personallyNo obligation

Most organisations start with a fixed-price Agent-Readiness Audit · £30k–£90k · 6–8 weeks