United Kingdom - Generative AI Framework
Generative AI Framework for HMG
United Kingdom
RAI-GB-NA-GENAIHM-2024The Generative AI Framework for HMG is official UK government guidance published to help civil servants and public-sector bodies understand, procure, develop and deploy generative AI safely, securely and responsibly. It sets out ten core principles, practical guidance on procurement, risk assessment, human oversight and data protection considerations and highlights use-cases to avoid. (gov.uk)
Summary
The Generative AI Framework for HMG (published 18 January 2024 by the Cabinet Office in collaboration with the Government Digital Service and the Central Digital & Data Office) is non-statutory guidance for UK central government departments and public-sector organisations on the safe and responsible adoption of generative AI technologies. The document provides an accessible primer on what generative AI (with a focus on large language models) is, identifies limitations and risks (accuracy, bias, privacy, security and environmental impacts), and sets out ten core principles intended to guide planning, procurement, development, deployment and ongoing assurance of AI-powered systems. It contains practical chapters on defining goals and use-cases, building teams, buying and procuring generative AI solutions in an emerging market, testing and validation, data management, legal and ethics considerations, and measures for secure deployment. Notably, the Framework includes explicit 'use cases to avoid' (for example: fully automated high-stakes decision-making, high-risk/high-impact applications without appropriate safeguards, low-latency control systems, and use cases requiring guaranteed high accuracy), and it mandates early involvement of legal, data protection and security specialists during project scoping. Although framed as guidance rather than law, the Framework requires adoption of documented governance, risk assessment and assurance practices, including the creation of inventories, ethics committees or AI governance boards, transparency measures such as the Algorithmic Transparency Recording Standard where applicable, human oversight arrangements and testing regimes to detect bias, safety failures and misinformation. The Framework was published as a living document intended to be updated as best practice evolves; it was later withdrawn and explicitly superseded by the broader "AI Playbook for the UK Government" (published 10 February 2025) which expands the guidance to cover a wider range of AI technologies while preserving the core principles. The primary text and accompanying artefacts (posters, procurement guidance and the PDF report) remain important reference points for public-sector AI governance, procurement teams and project leads. ([gov.uk](https://www.gov.uk/government/publications/generative-ai-framework-for-hmg))
Full article
Read full text ↗Overview
The Generative AI Framework for HMG is a government guidance document designed to help civil servants, central government departments and public-sector bodies understand, procure and use generative AI in a safe, secure and ethically responsible way. It emphasises ten core principles — including knowing tool limitations, lawful and ethical use, secure deployment and meaningful human control — and aims to be a living resource that will be updated as learning and best practice evolve. The Framework focuses on generative AI and large language models (LLMs) given their rapid adoption and practical utility across many government tasks, but its principles are broadly applicable to other AI forms. Readers are directed to practical resources (posters, procurement guidance and case studies) and to cross-government services and standards such as the Algorithmic Transparency Recording Standard and other departmental guidance. See the original publication on GOV.UK for the full report and PDFs: Generative AI Framework for HMG (GOV.UK).
Definitions
The Framework defines key terminology used across the guidance: 'generative AI' (systems that can generate text, images, audio, code or video), 'large language models' (LLMs) as a prominent subclass of generative models, 'meaningful human control' (human roles and decision points appropriate to the context), 'high-risk/high-impact' applications (uses that could materially harm health, safety, fundamental rights or the environment), 'data minimisation' and 'purpose limitation' aligned with data protection law. It also distinguishes between exploratory or productivity-enhancing uses and production deployments where assurance requirements are proportionately higher.
Governance and Institutional Framework
The Framework sets out a recommended governance architecture for public-sector AI use. It recommends departmental-level governance (AI or data boards, or AI representation on existing boards), the creation of ethics committees or review functions, and roles for technology, legal, data protection and security teams. It asks organisations to maintain AI/ML inventories to track installed or procured systems, to include AI-specific checks in existing assurance processes and to ensure senior stakeholder visibility. The document also directs teams to collaborate across government communities of practice, leverage central guidance and training, and to consider procurement and commercial colleagues early in projects. For central policy materials, the Framework and its attachments are hosted on GOV.UK: Generative AI Framework for HMG (GOV.UK). The Framework was produced by the Cabinet Office with input from DSIT, GDS, CDDO and a wide set of departments and arm’s-length bodies, ensuring alignment with wider public-sector assurance structures. It identifies the Algorithmic Transparency Recording Standard for public-facing decision-making systems and recommends documentation consistent with national standards.
Key Focus Areas
The Framework is organised around practical focus areas: (1) situational awareness — understanding what generative AI can and cannot do, (2) procurement and supplier management — specifying requirements, avoiding vendor lock-in, and aligning procurement with ethics and assurance, (3) data governance — managing training, input and output data flows, privacy and minimisation, (4) security and operational resilience — ensuring secure hosting, access controls, filtering and monitoring, (5) testing and validation — establishing testing plans for accuracy, bias, robustness and adversarial threats, (6) human oversight — maintaining appropriate human roles where decisions affect individuals' rights or safety, (7) transparency and explainability — documenting model purpose and limitations and using ATRS when relevant, (8) lifecycle management and incident response — ensuring monitoring, patching and rollback procedures, and (9) sustainability considerations — measuring and mitigating environmental impact. Each area contains checklists and practical advice for teams building or adopting generative AI systems. The Framework explicitly lists use-cases to avoid (for example fully automated high-stakes decisions and low-latency safety-critical control systems) and underscores that generative AI is optimised for plausibility rather than guaranteed accuracy.
Implementation Framework
Implementation guidance is pragmatic: project teams should start with a clear problem statement, undertake a proportional risk assessment, convene cross-functional experts (legal, security, data protection, subject-matter specialists), and document requirements for suppliers. The Framework provides procurement-specific advice for working in an emerging market: draft clear acceptance criteria, specify minimum security and data protection obligations, require vendor evidence for training data provenance where possible, and plan for audits and contractual remedies. Teams are instructed to adopt formal testing regimens (unit, integration, safety and adversarial testing), create sample datasets for verification, and document decisions and assurance artefacts (model cards, data cards, audit trails). When a system informs decisions affecting the public, transparency records and user-facing notices are required in line with departmental policies and the Algorithmic Transparency Recording Standard.
Monitoring and Evaluation
The Framework requires ongoing monitoring across quality, fairness and security dimensions. It recommends establishing KPIs for correctness, hallucination/error rates, bias metrics and user satisfaction; scheduled revalidation (for drift and retraining needs); continuous security scanning and logging; and appropriate escalation channels for incidents. Teams should retain evidence of testing and monitoring and perform post-deployment reviews to capture learnings. For centrally maintained updates and community resources, teams should consult GOV.UK and cross-government AI communities.
Penalties, Liability, and Appeals
The Framework itself is non-statutory guidance and does not prescribe criminal penalties; it instead requires compliance with applicable law (for example data protection legislation enforced by the Information Commissioner’s Office) and standard departmental accountability mechanisms (internal governance, procurement sanctions and professional disciplinary processes). Liability and redress for harms arising from AI deployments are governed by existing legal frameworks (data protection law, consumer and administrative law, sector-specific regulation). The Framework cross-references legal and ethical considerations and advises teams to seek legal advice early to clarify liability, contractual remedies and obligations to affected individuals.
Relationship to Other Instruments
The Framework sits alongside the UK AI regulatory white paper, the National AI Strategy, departmental data and security policies, the Algorithmic Transparency Recording Standard and sector-specific guidance (for example NHS, HMCTS or financial regulators where applicable). It was explicitly superseded as core cross-government guidance by the broader "Artificial Intelligence Playbook for the UK Government" on publication in February 2025. Teams are advised to use the Framework alongside sectoral regulation and the ICO's guidance on AI and personal data. See the Playbook: AI Playbook for the UK Government (GOV.UK).
International Alignment
The Framework recognises international initiatives (AI safety dialogues, OECD principles and other multilateral fora) and recommends that public-sector adoption aligns with domestic law while considering interoperability with international standards and supplier obligations. It encourages engagement with industry, academia and international partners to accelerate shared best practice in safety testing, transparency artefacts and standards for provenance and model description. The document emphasises that the UK's pro-innovation regulatory approach should remain compatible with international frameworks to facilitate cross-border procurement and research collaboration.
Implementation Timeline
| Event | Date |
|---|---|
| Publication of Generative AI Framework for HMG (PDF/HTML) | 2024-01-18 |
| Guidance updated / linked from civil service guidance | 2024-01 to 2024-02 (ongoing updates) |
| Framework withdrawn and superseded by AI Playbook for the UK Government | 2025-02-10 |
Sources and References
| Source | Type |
|---|---|
| Generative AI framework for HM Government (PDF) | Primary Source |
| Generative AI Framework for HMG (HTML) | Primary Source |
| Artificial Intelligence Playbook for the UK Government (AI Playbook) | Primary Source |
Requirements for a company
What an organisation has to do under United Kingdom - Generative AI Framework, at a glance. Not legal advice.
Related Regulations
Artificial Intelligence Playbook for the UK Government
United Kingdom96% similar
Guidance to civil servants on use of generative AI
United Kingdom95% similar
Responsible AI Guidance for the Public Service: GenAI
New Zealand92% similar
Generative AI Guidelines for Government (SDAIA)
Saudi Arabia91% similar
Government response to the AI regulation white paper (AI regulation: government response)
United Kingdom91% similar
© Regulations.AI · updated on 13-Jun-2026