United Kingdom - AI Playbook
Artificial Intelligence Playbook for the UK Government
United Kingdom
RAI-GB-NA-AIPUGXX-2025The AI Playbook for the UK Government is official cross‑government guidance published by the Government Digital Service on 10 February 2025 that replaces and expands the Generative AI Framework for HMG. It sets 10 principles, practical controls, procurement and assurance guidance to help central government and in‑scope public bodies select, buy, deploy and govern AI systems safely, securely and ethically.
Summary
Read full text ↗Plain English
Overview
The "Artificial Intelligence Playbook for the UK Government" (published 10 February 2025) is a cross‑government practical guidance package produced by the Government Digital Service to help civil servants and public sector organisations use AI systems safely, ethically and securely. The Playbook supersedes and expands the earlier Generative AI Framework for HMG (January 2024), and sits alongside the wider policy work such as the AI Opportunities Action Plan (Jan 2025). It sets out 10 core principles, offers lifecycle‑based operational guidance (including procurement and assurance), and provides templates, case studies and links to further technical and ethical resources. The Playbook is intended as a living resource: departments are encouraged to reuse materials, contribute case studies, and update internal processes in line with the guidance.
Definitions
The Playbook adopts internationally‑recognised definitions of AI (consistent with OECD and UK Government usage): an AI system is a machine‑based system that, for explicit or implicit objectives, infers from inputs how to generate outputs (predictions, content, recommendations or decisions) that can influence physical or virtual environments. The Playbook distinguishes fields such as machine learning, deep learning, generative models, symbolic AI and hybrid approaches; it clarifies terms including "model", "training data", "inference", "hallucination", "prompt injection", "data poisoning" and "meaningful human control." These definitions underpin lifecycle guidance and risk assessments throughout the Playbook.
Governance and Institutional Framework
The Playbook prescribes a layered governance approach: project‑level governance (clear project leads, multi‑disciplinary teams, security and legal owners), programme‑level assurance (AI review boards or programme boards with escalation routes), and departmental oversight (senior responsible owner and alignment with existing departmental governance). It references existing central standards and assurance functions (for example, the Government Digital Service, the Department for Science, Innovation and Technology (DSIT), the Cabinet Office, and assurance teams across departments). For transparency it instructs central departments and certain arm's length bodies in scope to record algorithmic tools in the Algorithmic Transparency Recording Standard (ATRS) and to publish appropriate public‑facing information. The Playbook also recommends establishing documented review gates (design, security testing, privacy impact assessment, pre‑deployment review) and re‑assessment schedules during operation to manage model drift, performance regression and emergent harms.
Key Focus Areas
The Playbook concentrates on these operational domains: risk management (systematic risk registers and harm matrices across safety, privacy, fairness, security, environmental impact and societal wellbeing); procurement and supplier management (assuring model provenance, rights to data and IP, supply chain security and contractual warranties); data governance (data minimisation, retention, anonymisation, bias analysis and logging for auditability); security (adversarial threats, prompt injection, data exfiltration and model theft; aligns with Secure by Design and the Government Cyber Security Strategy); human factors and meaningful human control (clear role definitions, escalation, human‑in‑the‑loop procedures and fail‑safe designs); testing and evaluation (dataset holdouts, red‑teaming, penetration and adversarial tests, user acceptance and accessibility testing); transparency and public engagement (public notices, ATRS entries, explanation approaches and user research); and workforce capability (training, cross‑functional staffing and centres of excellence). The Playbook also stresses environmental sustainability considerations for compute and model selection, recommending proportionality in compute‑intensive choices where alternatives exist.
Implementation Framework
The Playbook provides a staged implementation pathway: stage 0 (problem definition and user research), stage 1 (feasibility and ethics review), stage 2 (procurement and supplier due diligence), stage 3 (development, testing and security validation), stage 4 (deployment with monitoring and incident plans), and stage 5 (decommissioning and knowledge capture). For each stage the Playbook presents recommended artefacts (business case, AI risk assessment, privacy impact assessment, model card, test reports, ATRS entry) and assurance gates. It offers procurement‑specific advice including recommended contract clauses, model provenance requirements, data handling and audit rights, and guidance on when to favour in‑house development versus vetted suppliers. The Playbook also encourages departments to reuse multi‑government components and share infrastructure through cross‑government arrangements to reduce duplicated risk and increase consistency.
Monitoring and Evaluation
The Playbook instructs continuous monitoring for performance, fairness, safety and security: maintain monitoring dashboards, drift detection, logging for reproducibility, periodic re‑validation and triggered re‑assessment for incidents. It encourages teams to implement automated and manual monitoring streams, to collect user feedback, and to report significant adverse incidents via internal incident processes and to relevant external regulators when required (for example ICO for data breaches). The Playbook also urges central collation of lessons learned and regular updates to the Playbook based on operational experiences, evolving threat landscapes and new legal or technical guidance.
Penalties, Liability, and Appeals
As guidance, the Playbook does not itself create statutory penalties, but it clarifies regulatory and legal exposures for non‑compliance with statutory duties (notably data protection obligations under the UK GDPR and the Data Protection Act 2018). Departments are warned that failures can lead to ICO enforcement actions (including fines and corrective orders), contractual remedies and supplier liabilities, internal disciplinary and governance consequences, operational shutdowns, and reputational damage. The Playbook advises establishing clear internal escalation and appeals processes where decisions are contested, and documenting rationale to support legal defensibility of algorithmic decisions.
Relationship to Other Instruments
The Playbook situates itself alongside and references multiple instruments: it expands the earlier Generative AI Framework for HMG (now superseded), maps to the AI Opportunities Action Plan, aligns with the Government Cyber Security Strategy and Secure by Design principles, and points to ICO materials (including AI auditing guidance) and co‑produced explainability guidance from The Alan Turing Institute and the ICO. The Playbook recommends that departmental policies (security, procurement, ethics and privacy) be updated to incorporate its practice recommendations.
International Alignment
The Playbook references international definitions and good practice (OECD AI Principles, co‑operation forums) and encourages alignment with cross‑jurisdictional standards to maintain interoperability with allies and suppliers. It recognises the evolving international regulatory landscape and instructs teams to consider export controls, data transfer rules and global supply chain risks. The Playbook is framed to be compatible with proposed domestic regulatory approaches (the UK’s pro‑innovation regulatory white paper) while aiming to keep public sector practice interoperable with international norms.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| Publication of Playbook | 2025-02-10 | Official GOV.UK publication by Government Digital Service |
| Departments adopt internal processes | 2025 Q2-Q4 | Suggested period for departmental policy alignment and initial training |
| First annual review / update | 2026-02-10 | Playbook published as living document; review based on operational lessons |
Compliance Checklist
| Requirement | Compliant (Y/N) | Evidence |
|---|---|---|
| Business case and user research completed | Documented user research and business case | |
| AI risk assessment and mitigation plan | Risk register and mitigation logs | |
| Privacy Impact Assessment and ICO considerations | PIA document and ICO consultation notes | |
| Security testing and Secure by Design alignment | Pen test reports and security acceptance | |
| ATRS entry where in scope | ATRS record link | |
| Model and data documentation (model card/data card) | Published or internal documentation |
Sources and References
| Source | Type |
|---|---|
| AI Playbook for the UK Government (GOV.UK) | Primary Source |
| Generative AI Framework for HMG (Jan 2024) | Primary Source |
| AI Opportunities Action Plan (Jan 2025) | Primary Source |
The UK Government's AI Playbook provides practical guidance for central government departments and in-scope public bodies on how to safely, ethically, and securely select, buy, deploy, and manage Artificial Intelligence systems. This comprehensive guidance, published by the Government Digital Service, replaces an earlier framework and aims to standardise AI usage across the public sector.
The Playbook applies to all central government departments and relevant arm's length bodies, guiding civil servants and public sector organisations in their use of AI. It sets out ten core principles and offers detailed operational advice covering the entire AI lifecycle, from problem definition and procurement to deployment and decommissioning. Key obligations include: - Establishing a layered governance structure with clear project leads and review boards. - Systematically managing risks by maintaining registers and harm matrices covering safety, privacy, fairness, and security. - Ensuring meaningful human control, with clear roles, escalation paths, and human-in-the-loop procedures. - Recording algorithmic tools in the Algorithmic Transparency Recording Standard (ATRS) and publishing public-facing information where applicable. - Rigorous procurement processes, including assuring model provenance, data rights, and supply chain security.
The Playbook was published and became effective on February 10, 2025, with departments expected to align their internal processes throughout 2025. While the Playbook itself doesn't impose direct statutory penalties, non-compliance with its recommendations can lead to significant indirect consequences. These include enforcement actions and fines from regulators like the Information Commissioner's Office (ICO) for data protection breaches, contractual liabilities, internal disciplinary actions, operational shutdowns, and severe reputational damage. A practical pitfall for teams is the requirement for continuous monitoring and re-assessment of AI systems to manage issues like 'model drift' and 'performance regression', ensuring ongoing safety and effectiveness.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 13 marked completePlain-English obligations under United Kingdom - AI Playbook. Not legal advice — verify against the official text before relying on it.
- #1CriticalMonitoring and Evaluation
Applies to: Civil servants and public sector organisations using AI systems.
“...and to report significant adverse incidents via internal incident processes and to relevant external regulators when required (for example ICO for data breaches).”
- #2CriticalKey Focus Areas
Applies to: Civil servants and public sector organisations using AI systems.
“data governance (data minimisation, retention, anonymisation, bias analysis and logging for auditability)”
- #3ImportantGovernance and Institutional Framework
Applies to: Central departments and certain arm's length bodies in scope.
“For transparency it instructs central departments and certain arm's length bodies in scope to record algorithmic tools in the Algorithmic Transparency Recording Standard (ATRS)...”
- #4ImportantGovernance and Institutional Framework
Applies to: Central departments and certain arm's length bodies in scope.
“...and to publish appropriate public‑facing information.”
- #5ImportantKey Focus Areas
Applies to: Civil servants and public sector organisations using AI systems.
“risk management (systematic risk registers and harm matrices across safety, privacy, fairness, security, environmental impact and societal wellbeing)”
- #6ImportantMonitoring and Evaluation
Applies to: Civil servants and public sector organisations using AI systems.
“The Playbook instructs continuous monitoring for performance, fairness, safety and security: maintain monitoring dashboards, drift detection, logging for reproducibility...”
- #7ImportantKey Focus Areas⏰ Before deployment
Applies to: Civil servants and public sector organisations using AI systems.
“testing and evaluation (dataset holdouts, red‑teaming, penetration and adversarial tests, user acceptance and accessibility testing)”
- #8ImportantKey Focus Areas⏰ Before placing on market
Applies to: Civil servants and public sector organisations procuring AI systems.
“procurement and supplier management (assuring model provenance, rights to data and IP, supply chain security and contractual warranties)”
- #9ImportantKey Focus Areas
Applies to: Civil servants and public sector organisations using AI systems.
“security (adversarial threats, prompt injection, data exfiltration and model theft; aligns with Secure by Design and the Government Cyber Security Strategy)”
- #10ImportantInternational Alignment
Applies to: Civil servants and public sector organisations using AI systems.
“...and instructs teams to consider export controls, data transfer rules and global supply chain risks.”
- #11ImportantPenalties, Liability, and Appeals
Applies to: Civil servants and public sector organisations using AI systems.
“...and documenting rationale to support legal defensibility of algorithmic decisions.”
- #12RecommendedGovernance and Institutional Framework
Applies to: Civil servants and public sector organisations using AI systems.
“The Playbook also recommends establishing documented review gates (design, security testing, privacy impact assessment, pre‑deployment review)...”
- #13RecommendedRelationship to Other Instruments⏰ Dec 31, 2025
Applies to: Civil servants and public sector organisations using AI systems.
“The Playbook recommends that departmental policies (security, procurement, ethics and privacy) be updated to incorporate its practice recommendations.”
Related Regulations
Generative AI Framework for HMG
United Kingdom96% similar
Guidance to civil servants on use of generative AI
United Kingdom94% similar
National AI Strategy - AI Action Plan
United Kingdom92% similar
Guidelines for the Responsible Use of AI in the Public Service
Ireland92% similar
Government response to the AI regulation white paper (AI regulation: government response)
United Kingdom91% similar
© Regulations.AI — created on 21-Jul-2026