Using AI in government contracting without creating risk

Person at a desk reviewing a printed contract with a laptop open beside them
TL;DR

UK government procurement guidance now asks suppliers to declare how they use AI in delivery and build appropriate controls into contract terms. For a small services firm bidding on public-sector work, this means AI is a governance question at tender stage, not just an operational one during delivery. The ICO, NCSC, and Cabinet Office guidance all point the same direction: transparency, human oversight, and data controls cannot be afterthoughts.

Key takeaways

- The UK government now includes AI disclosure questions in public-sector tenders, with Cabinet Office guidance asking suppliers to declare AI use and accept safeguards in contract terms. - Small services firms using third-party AI tools must be able to explain model purpose, data flows, and human oversight to public-sector buyers following government procurement guidance. - UK GDPR applies fully to AI systems that process personal data, with the ICO expecting fairness, transparency, accuracy, and accountability regardless of whether AI is central or incidental to delivery. - The governance burden is proportionate: internal drafting tools with no client data and no impact on contract outputs sit at lower risk than AI used in decision-support, triage, or client-facing work. - Two documents set the benchmark for well-informed public-sector buyers: the government AI procurement guidelines (2020) and the AI Playbook for UK Government (February 2025), both available on GOV.UK.

A services firm owner opens a government tender pack and finds a section they weren’t expecting: questions about AI. Are they using it in delivery? Where? How is data handled? Who reviews outputs? They’re already using a language model to help draft the proposal itself. The gap between what they’re doing and what they’re being asked to account for suddenly feels very visible.

This is a relatively new kind of discomfort. The UK government has embedded AI disclosure into its procurement guidance, and for smaller services firms the question is no longer whether this matters but exactly where it bites and how seriously to prepare.

What is AI disclosure in government contracting?

The UK government now asks suppliers to declare how they plan to use AI in delivering a contract. Procurement Policy Note guidance from the Cabinet Office tells commercial teams to include optional questions about supplier AI use where AI in delivery is plausible, and to build AI-specific safeguards into award criteria and contract terms where the risk warrants it.

This framework grew out of a procurement landscape where AI was entering service delivery without visibility or governance. The government’s AI procurement guidelines, published in 2020, set out themes for assessing AI viability and embedding standards into contracts. The AI Playbook for UK Government, launched in February 2025, reinforced that expectation across departments and public bodies. The Playbook explicitly requires teams to understand, monitor, and mitigate AI risks, involve assurance teams early, and maintain programme-level oversight. Suppliers sit downstream: the governance architecture buyers build for themselves shapes what they look for in the firms they contract with.

The practical consequence is that a tender response silent on AI, while the delivery model relies on it, creates exposure later. The Cabinet Office guidance also says commercial teams may require suppliers to declare AI use and provide further detail. If the buyer later asks to audit data handling or review how human oversight worked, a firm that never addressed these questions is in a weaker position.

Why does this create risk for a smaller services firm?

Public-sector buyers working from government guidance now expect suppliers to explain what their AI does, where data flows, who reviews outputs, and how errors are escalated. For a small services firm using third-party AI tools, this means a black-box supplier arrangement, where you cannot describe the model’s purpose, data handling, or human oversight, does not satisfy that expectation at tender stage or during delivery.

The Government’s AI Playbook makes this concrete. It requires departments to maintain organisation-specific security and data-handling policies, documented review processes, escalation routes, and oversight at programme or board level. Buyers building this governance architecture naturally look for compatible controls in their suppliers. Documentation ready to share when asked is the practical minimum. A services firm that cannot describe its own AI governance is answering a question the buyer is already asking.

Data protection adds a second layer. The ICO has confirmed that UK GDPR principles apply fully to AI systems that process personal data. Fairness, transparency, accuracy, and accountability are requirements regardless of whether the processing is automated. The ICO’s AI procurement guidance goes further, pointing to data protection impact assessments, meaningful human review, and supplier management as practical requirements for organisations deploying AI in service delivery.

Where will you actually encounter this in a tender?

AI governance in public-sector contracting surfaces at three points. At bid stage, the tender pack may include questions about AI use in delivery, which systems are involved, and how data is handled. At contract negotiation, buyers may request specific clauses on data flows, output review, and logging rights. During delivery, where audit rights or escalation routes are written into the contract, you are expected to perform against them.

The NCSC’s AI security guidance adds a technical dimension to all three stages. Its work on prompt injection, data leakage, insecure integration, and supply-chain risk translates directly into the questions a well-briefed procurement team will ask. If the buyer’s commercial team has read NCSC guidance, they will want to know about model access controls, logging practices, and what happens when a data boundary is breached.

The CMA’s position on AI claims is relevant at bid stage. If your proposal describes specific AI-driven outcomes, those claims need to be accurate and defensible. The CMA has said businesses must not exaggerate AI capabilities, must be clear about limitations, and must take responsibility for outputs. A bid that promises AI precision it cannot deliver creates risk before the contract is signed.

When do you need to act on this, and when is the risk lower?

The governance burden scales with two variables: how sensitive the data is that your AI processes, and whether the AI is doing decision-support work or purely internal drafting. A language model helping your team write first-draft documents, with no client data fed in and no effect on what the buyer receives, sits at the lower end of the risk spectrum. AI processing client submissions or recommending outcomes for beneficiaries sits at the high end.

The government guidance is consistent on this distinction. The AI Playbook emphasises suitability assessments, which means using AI where it is genuinely the right tool at the right risk level. If your AI use is wholly internal and has no effect on the contracted service, the procurement burden is lighter. Where any AI component touches what the buyer is paying for, transparency, human oversight, and data controls become requirements, not optional extras.

A separate consideration applies for firms with FCA-regulated activities or those working with financial services clients. The FCA has signalled active scrutiny of AI and data-driven decision-making under its operational resilience and third-party risk frameworks. A services firm supporting financial services clients, even in a delivery capacity, should check where those obligations extend to them.

UK GDPR, enforced by the ICO, is the foundational layer for any AI system that processes personal data. The core principles apply regardless of whether you are the data controller or processor, and regardless of whether AI is incidental or central to the service you deliver. The ICO has published dedicated guidance covering both AI deployment and AI procurement, including DPIAs, meaningful human review, and supplier management expectations.

The NCSC’s AI security collection and its guidance on securing large language model applications cover the specific technical risk surface, including prompt injection, data leakage, and supply-chain vulnerabilities. These risks translate directly into contract clauses about logging, model access controls, and incident response. A cyber assurance requirement in a public-sector contract will typically reference NCSC guidance as the expected standard.

The EU AI Act matters if your firm works with EU public-sector buyers or handles contracts where EU law applies. It creates obligations for high-risk AI systems and transparency requirements for certain use cases. UK firms are not automatically exempt when the end-user is in the EU.

For the government guidance itself, two documents are worth bookmarking: the AI procurement guidelines PDF published in 2020, and the AI Playbook for UK Government published in February 2025. Both are on GOV.UK. The two-step pattern running through all of it is disclosure at tender and governance built into contract terms. Both steps belong to the firm that signs the contract, not the AI supplier it uses.

Sources

- Cabinet Office / Civil Service (2024). Procurement Policy Note: Improving transparency of AI use in procurement. Guidance on supplier AI disclosure and safeguards in public-sector tenders. https://www.procurementpathway.civilservice.gov.uk/documents/ppn/improving-transparency-of-ai-use-in-procurement/finalise-and-publish-procurement-pack - UK Government (2020). Guidelines for AI procurement. PDF guidance setting themes for assessing AI viability and embedding standards into public-sector contracts. https://assets.publishing.service.gov.uk/media/60b356228fa8f5489723d170/Guidelines_for_AI_procurement.pdf - Government Digital Service (2025). Artificial Intelligence Playbook for the UK Government. Sets out principles for safe and effective AI use across departments and public bodies, including documentation, oversight, and risk management. https://www.gov.uk/government/publications/ai-playbook-for-the-uk-government/artificial-intelligence-playbook-for-the-uk-government-html - Government Digital Service (2025). Launching the AI Playbook for the UK Government. Launch note describing the Playbook's scope and intent, published 10 February 2025. https://gds.blog.gov.uk/2025/02/10/launching-the-artificial-intelligence-playbook-for-the-uk-government/ - Information Commissioner's Office. AI and data protection guidance. Covers fairness, transparency, accuracy, and accountability requirements under UK GDPR for AI systems. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/ - Information Commissioner's Office. Procuring AI: guidance for organisations. Covers DPIAs, human review, and supplier management expectations for organisations deploying AI. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/procuring-ai/ - National Cyber Security Centre. Artificial intelligence security guidance collection. Covers prompt injection, data leakage, and supply-chain risk relevant to AI procurement decisions. https://www.ncsc.gov.uk/collection/artificial-intelligence - National Cyber Security Centre. Guidelines for secure AI system development. Practical security recommendations for organisations using or deploying large language model applications. https://www.ncsc.gov.uk/guidance/secure-llm-applications - Competition and Markets Authority (2024). AI and consumer protection: the CMA's perspective. Guidance on AI capability claims and the obligations businesses carry for AI-generated outputs. https://www.gov.uk/government/publications/ai-and-consumer-protection-the-cmas-perspective - European Parliament and Council of the EU (2024). Regulation (EU) 2024/1689 (EU AI Act). Legislation establishing risk categories and obligations for AI systems used in the EU, relevant to UK firms serving EU buyers. https://eur-lex.europa.eu/eli/reg/2024/1689/oj

Frequently asked questions

Does the UK government require suppliers to declare AI use in government contracts?

Procurement Policy Note guidance from the Cabinet Office tells commercial teams to include disclosure questions about supplier AI use where AI in delivery is plausible. Commercial teams may also require suppliers to provide further detail and to accept AI-related safeguards in contract terms. Whether these are mandatory or advisory varies by contract type and buyer, but the direction of travel is clearly towards mandatory transparency for higher-risk procurement.

Does UK GDPR apply when a services firm uses AI in a government contract?

Yes. The ICO has confirmed that UK GDPR principles apply fully to AI systems that process personal data. Lawfulness, fairness, transparency, accuracy, and accountability all apply. The ICO's AI procurement guidance also expects data protection impact assessments, meaningful human review, and supplier management from organisations deploying AI in service delivery. The fact that processing is automated via a model does not change the legal obligations.

What is the EU AI Act and does it apply to UK-based services firms?

The EU AI Act creates obligations for high-risk AI systems and transparency requirements for certain AI use cases. UK-based firms are not automatically exempt. If your firm works with EU public-sector buyers, provides services where EU law applies, or supplies AI products into the EU market, the Act may be relevant. UK firms serving EU buyers should map their AI use cases against the Act's risk categories before assuming they are outside scope.

This post is general information and education only, not legal, regulatory, financial, or other professional advice. Regulations evolve, fee benchmarks shift, and every situation is different, so please take qualified professional advice before acting on anything you read here. See the Terms of Use for the full position.

Ready to talk it through?

Book a free 30 minute conversation. No pitch, no pressure, just a useful chat about where AI fits in your business.

Book a conversation

Related reading

If any of this sounds familiar, let's talk.

The next step is a conversation. No pitch, no pressure. Just an honest discussion about where you are and whether I can help.

Book a conversation