Common questions about AI adoption
Browse common questions about adopting AI in government. Each answer includes a snippet from the AI Playbook for the UK Government and a deep link to the relevant section.
This explorer currently covers one source. More public sector AI guidance will be added over time.
Categories
Getting started
What is AI, and what are its main limitations in a government context?
You should learn what AI can and cannot do before using it. AI systems currently lack reasoning and contextual awareness, are not guaranteed to be accurate, and have limitations that vary by tool and context.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Principle 1: You know what AI is and what its limitations are
When is AI the right tool for the job, and when should I use something else?
Choose the most appropriate technology for the need. Be open to AI where it helps, but also open to concluding that established technologies are a better fit.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Principle 6: You use the right tool for the job
What kinds of AI use cases work well in government?
Use cases should be led by business and user needs. Focus on problems that only AI can solve well, or where AI offers significant advantages — for example pattern detection in large datasets, complex dynamic decisions, or personalisation.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Identifying use cases for AI
Which AI use cases should I avoid?
Avoid fully automated decision making for significant decisions, and do not use AI on its own in high-risk areas that could harm health, safety, fundamental rights or the environment.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Use cases to avoid
Do I need an AI strategy or governance board before I start my first project?
Support structures do not need to be fully mature before your first project, but you should have enough control to use AI safely. Establish strategy, principles, governance, communication, sourcing and training as you go.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Creating the AI support structure
What skills and roles do I need on an AI project team?
Build a multidisciplinary team covering user needs, delivery, data, engineering, design, and legal/commercial/security/ethics expertise. Balance technical and domain expertise and include diverse viewpoints to help spot bias.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Building the team
Where can civil servants get training on AI?
Free AI courses are available on Civil Service Learning and through Government Campus learning frameworks. Senior civil servants can also use the Digital Excellence Programme AI course.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Learning resources
Lawful, ethical and responsible use
Can I use AI to process personal data?
Yes, but only lawfully and with data protection advice from the start. AI systems can process personal data, so you must protect it, comply with data protection law, and minimise privacy intrusion from the outset.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Principle 2: You use AI lawfully, ethically and responsibly
Do I need a Data Protection Impact Assessment (DPIA) before using AI?
Before implementing AI solutions you need to undertake a DPIA. UK GDPR also requires a DPIA for certain high-risk processing, and the ICO requires one when using innovative technologies.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Lawfulness and purpose limitation
Can I reuse existing personal data to train or run an AI system?
Only if the new purpose is compatible with the original purpose for collection. Assess expectations, data type, impact on people, and whether extra safeguards are needed.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Lawfulness and purpose limitation
Can AI make automated decisions that affect people?
Solely automated decisions with legal or similarly significant effects are restricted under UK GDPR Article 22. Where AI affects someone’s legal status or rights, it must only support decisions made by a human.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Human oversight
How much human oversight do I need when using AI in decision making?
You need meaningful human control at the right stages, including validation of high-risk decisions and ways for users to report issues and trigger human review.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Principle 4: You have meaningful human control at the right stages
Do I need to tell the public when we are using AI or algorithms?
Yes. Be open about where and how algorithms and AI are used in official duties, and clearly identify automated responses such as chatbot replies.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Principle 7: You are open and collaborative
Do I need to use the Algorithmic Transparency Recording Standard (ATRS)?
Central government departments and in-scope arm’s length bodies must use ATRS for algorithmic tools in decision-making. Other public bodies are encouraged to use it too.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Principle 7: You are open and collaborative
How do I manage bias and fairness in an AI system?
AI can reproduce bias from training data and produce unfair outputs. Consider all potential sources of bias across the life cycle, including unrepresentative datasets and unfair deployment impacts.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Principle 2: You use AI lawfully, ethically and responsibly
What equality and human rights issues should I consider when using AI?
Consider Equality Act and Public Sector Equality Duty obligations, and whether AI may affect Convention rights such as privacy or freedom of expression. Assess equality impacts early.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Equality issues
Do I need legal advice before starting an AI project?
Yes — seek legal advice early on development and use of AI, including equalities, fairness, intellectual property and other legal issues. Explain aims, capabilities and risks when you contact lawyers.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Principle 2: You use AI lawfully, ethically and responsibly
Security and safe use of tools
Can I put official or unpublished information into public tools like ChatGPT?
No. When using public AI applications you must not enter official information unless it has been published or is cleared for publication.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Public AI applications and web services
Can I use Microsoft Copilot, Slack GPT, or similar embedded AI features at work?
Only after understanding the product architecture and vendor mitigations, and after speaking with your security team. Embedded AI features bring their own security concerns.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Embedded AI applications
Are AI meeting transcription tools allowed?
Treat them as a serious data-leakage risk. Meeting organisers should verify attendees and state that third-party transcription tools are not allowed.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Embedded AI applications
Should I use a public AI API, a privately hosted model, or a managed platform?
It depends on control and risk. Public APIs still send data to a provider; private hosting keeps data in your environment but you own security and ops; managed platforms can offer private instances with stronger retention controls.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Privately hosted AI models
What are the main security risks of using AI in government?
AI-specific risks include data/model poisoning, data leakage, insecure AI tooling, prompt injection, perturbation attacks and hallucinations, as well as amplification of existing cyber risks.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Principle 3: You know how to use AI securely
How do I stop an AI system from leaking personal or sensitive data?
Control what data the model can access, prefer approaches that preserve user access controls (for example RAG/in-context learning), and apply additional security controls when using organisational data.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Working with your organisational data
How should I handle prompt injection and other generative AI-specific threats?
Assume prompts can subvert system instructions. Use filtering, logging and audit, and keep a human in the loop before automated actions are carried out.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Prompt injection
Can I trust generative AI outputs, or do they hallucinate?
Do not trust generative AI to produce factual content uncritically. Models can generate plausible but false information; train users not to rely exclusively on these outputs.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Hallucinations
Buying and building
Should I buy an AI product or build one in-house?
Decide based on the problem and commercial advice. Options include off-the-shelf products, AI bolted onto existing technology, outsourced builds, or co-creating with suppliers.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Specifying your requirements
When should I involve commercial colleagues in an AI project?
From the start. Get commercial advice early on partners, pricing, products and services, and keep ethical expectations consistent for in-house and procured systems.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Principle 8: You work with commercial colleagues from the start
How do I write a business case for an AI project?
Use the Green Book for larger investments (typically approaching £10m) and consider GDS agile business case guidance for smaller ones. Engage stakeholders first on whether AI is needed.
From the guidance
Source:
AI Playbook for the UK Government
Section:
AI business cases
What spend controls or approvals apply to AI and digital projects?
Digital and technology spend above £100,000 for public-facing services and £1 million otherwise must be assured through your assurance boards. Follow GDS spend approval guidance.
From the guidance
Source:
AI Playbook for the UK Government
Section:
AI business cases
How do I specify requirements when buying AI?
Start from the problem statement, cover data strategy/quality/bias, demand transparency about the supplier’s AI approach, plan for maintenance, IP, liabilities and avoiding vendor lock-in.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Specifying your requirements
Who owns the intellectual property if we develop or procure an AI solution?
Decide ownership and ongoing use rights at the outset, including how infringement risk and liability are shared between parties.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Intellectual property, including copyright
How do I avoid vendor lock-in when buying AI?
Build exit and portability into requirements and contracts from the start, including understanding the supplier’s approach and planning for transfer to successor suppliers.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Specifying your requirements
Delivery, assurance and operations
Do AI projects still need to meet the government Service Standard?
Yes. If you develop a service, you must use the government Service Standard, alongside wider technology and cloud security guidance.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Principle 5: You understand how to manage the full AI life cycle
How should I do user research for an AI product?
Use user research to check AI is the right tool, define metrics, prepare/evaluate data and outputs, assess usability and trust, and monitor the live service — keeping humans in the loop.
From the guidance
Source:
AI Playbook for the UK Government
Section:
User research for AI
How do I monitor an AI system once it is live?
Put ongoing performance monitoring in place, evidence that the system is operating as expected, and manage model updates through a controlled release process that can be rolled back.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Operational monitoring
What happens if the model drifts or starts performing worse over time?
Monitor for drift. Environments change over time and may require retraining or a new model; catch this early to reduce disruption.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Operational monitoring
How do I keep an inventory of AI systems in my organisation?
Maintain a live AI/ML systems inventory covering purpose, risks, data, ownership and key dates, in addition to ATRS transparency records where required.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Creating an AI systems inventory
Who is accountable if an AI system causes harm or makes a bad decision?
Your organisation needs clear ownership of risk and responsibility for mitigations and compliance. Connect with assurance teams early and document review and escalation routes.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Accountability
How do people challenge or seek redress for an AI-influenced decision?
Build contestability and redress into design so people can challenge outcomes and seek remedy. This sits alongside transparency, explainability and meaningful human oversight.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Principle 4: You have meaningful human control at the right stages
Collaboration and reuse
How do I find out what other departments are already doing with AI?
Join cross-government communities such as the AI community of practice, engage departments tackling similar problems, and review ATRS records and published case studies.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Principle 7: You are open and collaborative
Can I reuse AI code, models, or approaches from elsewhere in government?
Yes — the playbook encourages reusing ideas, code and infrastructure, and sharing inventories/case studies through the AI community of practice.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Principle 7: You are open and collaborative
Should I engage civil society, academia, or industry on my AI project?
Yes where possible. Engaging wider civil society, academia and industry helps ensure AI delivers public benefit and reflects people’s values and concerns.
From the guidance
Source:
AI Playbook for the UK Government
Section:
Principle 7: You are open and collaborative