United Kingdom - AI Playbook

Artificial Intelligence Playbook for the UK Government

United Kingdom

RAI-GB-NA-AIPUGXX-2025
Effective: February 10, 2025
In Force (Amended)(In Force (Amended))
GuidelineGovernance and OversightRisk ManagementAccountability and Documentation
Export PDF

The AI Playbook for the UK Government is official cross‑government guidance published by the Government Digital Service on 10 February 2025 that replaces and expands the Generative AI Framework for HMG. It sets 10 principles, practical controls, procurement and assurance guidance to help central government and in‑scope public bodies select, buy, deploy and govern AI systems safely, securely and ethically.

Overview

The "Artificial Intelligence Playbook for the UK Government" (published 10 February 2025) is a cross‑government practical guidance package produced by the Government Digital Service to help civil servants and public sector organisations use AI systems safely, ethically and securely. The Playbook supersedes and expands the earlier Generative AI Framework for HMG (January 2024), and sits alongside the wider policy work such as the AI Opportunities Action Plan (Jan 2025). It sets out 10 core principles, offers lifecycle‑based operational guidance (including procurement and assurance), and provides templates, case studies and links to further technical and ethical resources. The Playbook is intended as a living resource: departments are encouraged to reuse materials, contribute case studies, and update internal processes in line with the guidance.

Definitions

The Playbook adopts internationally‑recognised definitions of AI (consistent with OECD and UK Government usage): an AI system is a machine‑based system that, for explicit or implicit objectives, infers from inputs how to generate outputs (predictions, content, recommendations or decisions) that can influence physical or virtual environments. The Playbook distinguishes fields such as machine learning, deep learning, generative models, symbolic AI and hybrid approaches; it clarifies terms including "model", "training data", "inference", "hallucination", "prompt injection", "data poisoning" and "meaningful human control." These definitions underpin lifecycle guidance and risk assessments throughout the Playbook.

Governance and Institutional Framework

The Playbook prescribes a layered governance approach: project‑level governance (clear project leads, multi‑disciplinary teams, security and legal owners), programme‑level assurance (AI review boards or programme boards with escalation routes), and departmental oversight (senior responsible owner and alignment with existing departmental governance). It references existing central standards and assurance functions (for example, the Government Digital Service, the Department for Science, Innovation and Technology (DSIT), the Cabinet Office, and assurance teams across departments). For transparency it instructs central departments and certain arm's length bodies in scope to record algorithmic tools in the Algorithmic Transparency Recording Standard (ATRS) and to publish appropriate public‑facing information. The Playbook also recommends establishing documented review gates (design, security testing, privacy impact assessment, pre‑deployment review) and re‑assessment schedules during operation to manage model drift, performance regression and emergent harms.

Key Focus Areas

The Playbook concentrates on these operational domains: risk management (systematic risk registers and harm matrices across safety, privacy, fairness, security, environmental impact and societal wellbeing); procurement and supplier management (assuring model provenance, rights to data and IP, supply chain security and contractual warranties); data governance (data minimisation, retention, anonymisation, bias analysis and logging for auditability); security (adversarial threats, prompt injection, data exfiltration and model theft; aligns with Secure by Design and the Government Cyber Security Strategy); human factors and meaningful human control (clear role definitions, escalation, human‑in‑the‑loop procedures and fail‑safe designs); testing and evaluation (dataset holdouts, red‑teaming, penetration and adversarial tests, user acceptance and accessibility testing); transparency and public engagement (public notices, ATRS entries, explanation approaches and user research); and workforce capability (training, cross‑functional staffing and centres of excellence). The Playbook also stresses environmental sustainability considerations for compute and model selection, recommending proportionality in compute‑intensive choices where alternatives exist.

Implementation Framework

The Playbook provides a staged implementation pathway: stage 0 (problem definition and user research), stage 1 (feasibility and ethics review), stage 2 (procurement and supplier due diligence), stage 3 (development, testing and security validation), stage 4 (deployment with monitoring and incident plans), and stage 5 (decommissioning and knowledge capture). For each stage the Playbook presents recommended artefacts (business case, AI risk assessment, privacy impact assessment, model card, test reports, ATRS entry) and assurance gates. It offers procurement‑specific advice including recommended contract clauses, model provenance requirements, data handling and audit rights, and guidance on when to favour in‑house development versus vetted suppliers. The Playbook also encourages departments to reuse multi‑government components and share infrastructure through cross‑government arrangements to reduce duplicated risk and increase consistency.

Monitoring and Evaluation

The Playbook instructs continuous monitoring for performance, fairness, safety and security: maintain monitoring dashboards, drift detection, logging for reproducibility, periodic re‑validation and triggered re‑assessment for incidents. It encourages teams to implement automated and manual monitoring streams, to collect user feedback, and to report significant adverse incidents via internal incident processes and to relevant external regulators when required (for example ICO for data breaches). The Playbook also urges central collation of lessons learned and regular updates to the Playbook based on operational experiences, evolving threat landscapes and new legal or technical guidance.

Penalties, Liability, and Appeals

As guidance, the Playbook does not itself create statutory penalties, but it clarifies regulatory and legal exposures for non‑compliance with statutory duties (notably data protection obligations under the UK GDPR and the Data Protection Act 2018). Departments are warned that failures can lead to ICO enforcement actions (including fines and corrective orders), contractual remedies and supplier liabilities, internal disciplinary and governance consequences, operational shutdowns, and reputational damage. The Playbook advises establishing clear internal escalation and appeals processes where decisions are contested, and documenting rationale to support legal defensibility of algorithmic decisions.

Relationship to Other Instruments

The Playbook situates itself alongside and references multiple instruments: it expands the earlier Generative AI Framework for HMG (now superseded), maps to the AI Opportunities Action Plan, aligns with the Government Cyber Security Strategy and Secure by Design principles, and points to ICO materials (including AI auditing guidance) and co‑produced explainability guidance from The Alan Turing Institute and the ICO. The Playbook recommends that departmental policies (security, procurement, ethics and privacy) be updated to incorporate its practice recommendations.

International Alignment

The Playbook references international definitions and good practice (OECD AI Principles, co‑operation forums) and encourages alignment with cross‑jurisdictional standards to maintain interoperability with allies and suppliers. It recognises the evolving international regulatory landscape and instructs teams to consider export controls, data transfer rules and global supply chain risks. The Playbook is framed to be compatible with proposed domestic regulatory approaches (the UK’s pro‑innovation regulatory white paper) while aiming to keep public sector practice interoperable with international norms.

Implementation Timeline

MilestoneDateNotes
Publication of Playbook2025-02-10Official GOV.UK publication by Government Digital Service
Departments adopt internal processes2025 Q2-Q4Suggested period for departmental policy alignment and initial training
First annual review / update2026-02-10Playbook published as living document; review based on operational lessons

Compliance Checklist

RequirementCompliant (Y/N)Evidence
Business case and user research completedDocumented user research and business case
AI risk assessment and mitigation planRisk register and mitigation logs
Privacy Impact Assessment and ICO considerationsPIA document and ICO consultation notes
Security testing and Secure by Design alignmentPen test reports and security acceptance
ATRS entry where in scopeATRS record link
Model and data documentation (model card/data card)Published or internal documentation

Sources and References

SourceType
AI Playbook for the UK Government (GOV.UK)Primary Source
Generative AI Framework for HMG (Jan 2024)Primary Source
AI Opportunities Action Plan (Jan 2025)Primary Source
Plain English

The UK Government's AI Playbook provides practical guidance for central government departments and in-scope public bodies on how to safely, ethically, and securely select, buy, deploy, and manage Artificial Intelligence systems. This comprehensive guidance, published by the Government Digital Service, replaces an earlier framework and aims to standardise AI usage across the public sector.

The Playbook applies to all central government departments and relevant arm's length bodies, guiding civil servants and public sector organisations in their use of AI. It sets out ten core principles and offers detailed operational advice covering the entire AI lifecycle, from problem definition and procurement to deployment and decommissioning. Key obligations include: - Establishing a layered governance structure with clear project leads and review boards. - Systematically managing risks by maintaining registers and harm matrices covering safety, privacy, fairness, and security. - Ensuring meaningful human control, with clear roles, escalation paths, and human-in-the-loop procedures. - Recording algorithmic tools in the Algorithmic Transparency Recording Standard (ATRS) and publishing public-facing information where applicable. - Rigorous procurement processes, including assuring model provenance, data rights, and supply chain security.

The Playbook was published and became effective on February 10, 2025, with departments expected to align their internal processes throughout 2025. While the Playbook itself doesn't impose direct statutory penalties, non-compliance with its recommendations can lead to significant indirect consequences. These include enforcement actions and fines from regulators like the Information Commissioner's Office (ICO) for data protection breaches, contractual liabilities, internal disciplinary actions, operational shutdowns, and severe reputational damage. A practical pitfall for teams is the requirement for continuous monitoring and re-assessment of AI systems to manage issues like 'model drift' and 'performance regression', ensuring ongoing safety and effectiveness.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 13 marked complete

Plain-English obligations under United Kingdom - AI Playbook. Not legal advice — verify against the official text before relying on it.

  1. #1CriticalMonitoring and Evaluation

    Applies to: Civil servants and public sector organisations using AI systems.

    ...and to report significant adverse incidents via internal incident processes and to relevant external regulators when required (for example ICO for data breaches).
  2. #2CriticalKey Focus Areas

    Applies to: Civil servants and public sector organisations using AI systems.

    data governance (data minimisation, retention, anonymisation, bias analysis and logging for auditability)
  3. #3ImportantGovernance and Institutional Framework

    Applies to: Central departments and certain arm's length bodies in scope.

    For transparency it instructs central departments and certain arm's length bodies in scope to record algorithmic tools in the Algorithmic Transparency Recording Standard (ATRS)...
  4. #4ImportantGovernance and Institutional Framework

    Applies to: Central departments and certain arm's length bodies in scope.

    ...and to publish appropriate public‑facing information.
  5. #5ImportantKey Focus Areas

    Applies to: Civil servants and public sector organisations using AI systems.

    risk management (systematic risk registers and harm matrices across safety, privacy, fairness, security, environmental impact and societal wellbeing)
  6. #6ImportantMonitoring and Evaluation

    Applies to: Civil servants and public sector organisations using AI systems.

    The Playbook instructs continuous monitoring for performance, fairness, safety and security: maintain monitoring dashboards, drift detection, logging for reproducibility...
  7. #7ImportantKey Focus AreasBefore deployment

    Applies to: Civil servants and public sector organisations using AI systems.

    testing and evaluation (dataset holdouts, red‑teaming, penetration and adversarial tests, user acceptance and accessibility testing)
  8. #8ImportantKey Focus AreasBefore placing on market

    Applies to: Civil servants and public sector organisations procuring AI systems.

    procurement and supplier management (assuring model provenance, rights to data and IP, supply chain security and contractual warranties)
  9. #9ImportantKey Focus Areas

    Applies to: Civil servants and public sector organisations using AI systems.

    security (adversarial threats, prompt injection, data exfiltration and model theft; aligns with Secure by Design and the Government Cyber Security Strategy)
  10. #10ImportantInternational Alignment

    Applies to: Civil servants and public sector organisations using AI systems.

    ...and instructs teams to consider export controls, data transfer rules and global supply chain risks.
  11. #11ImportantPenalties, Liability, and Appeals

    Applies to: Civil servants and public sector organisations using AI systems.

    ...and documenting rationale to support legal defensibility of algorithmic decisions.
  12. #12RecommendedGovernance and Institutional Framework

    Applies to: Civil servants and public sector organisations using AI systems.

    The Playbook also recommends establishing documented review gates (design, security testing, privacy impact assessment, pre‑deployment review)...
  13. #13RecommendedRelationship to Other InstrumentsDec 31, 2025

    Applies to: Civil servants and public sector organisations using AI systems.

    The Playbook recommends that departmental policies (security, procurement, ethics and privacy) be updated to incorporate its practice recommendations.

© Regulations.AI — created on 21-Jul-2026