The UK public sector spends at least £14 billion a year on digital programmes and technology procurement, according to the National Audit Office. The NAO has also documented decades of poor progress on large-scale transformation. AI will not break that pattern unless the starting point changes. For central government departments, that means data readiness before vendor selection, and governance discipline from day one.
The spend is not the problem. The pattern is.
The National Audit Office's January 2025 report Government's approach to technology suppliers (HC 543, 16 January 2025) put a floor under the number: at least £14 billion a year in public sector digital programmes and technology procurement. The NAO also recorded "decades of poor progress and billions of pounds in cost increases" on large-scale digital transformation. AI sits squarely inside this spending envelope. The Cabinet Office AI Opportunities Action Plan, updated in January 2026, commits to upskilling ten million UK workers in AI by 2030, with over a million free AI courses delivered in the first year.
That is a different pattern of ambition to anything the public sector has tried before. The risk is that it lands on the same departmental foundations that produced the NAO's finding in the first place.
Policy is ahead of practice
Central government has published more AI governance material in the last eighteen months than in the preceding decade. The CDDO Data and AI Ethics Framework. The GDS AI Playbook. The Information Commissioner's Office Regulating AI, the ICO's strategic approach. The ICO is developing a statutory code of practice on AI and automated decision-making, gated on secondary legislation under the Data Use and Access Act and informed by the ICO's March 2026 consultation on draft ADM and profiling guidance. An agentic AI horizon-scanning report sits alongside it in the 2025-26 strategic plan.
The AI Safety Institute was renamed the AI Security Institute in February 2025, with its mission shifted from ethics and bias towards cyber fraud and state-level misuse. The direction of travel at the centre is clear.
On 9 April 2026, DSIT and the Government Digital Service published the Digital and Data Benefits Framework. It sits alongside HM Treasury's Green Book as the standard methodology for quantifying the benefits of digital and data programmes in public sector business cases. The framework is structured in five sections: AI, service transformation, data, capability, and technology with cyber and interoperability. Its AI section estimates £6.3 billion in potential annual Civil Service savings, £1.1 billion from cost reductions and £5.2 billion from productivity gains equivalent to 5.2 million working hours a year. That is the upside number every departmental AI business case will now be situated against.
The framework has changed the bar for departmental AI business cases overnight. The data section asks departments to evidence realised value, not projected value. The service transformation and interoperability sections are where most public sector business cases have historically been weakest. A department writing an AI business case today is being measured against a methodology that exposes exactly the layers where the data foundations have not been built.
Most departments cannot yet meet the bar these documents set. Not because they have not tried, but because the data foundations those frameworks assume were never built. That is the gap the next twelve months will expose.
The SRO reads this as an accountability problem. The CDDO lead reads it as a framework-compliance problem. The Chief Data Officer reads it as a data-stewardship problem. The next scrutiny point, NAO review or Parliamentary committee, will ask all three the same question.
Three areas where the data record decides the outcome
AI vendor selection as a data question. Procurement and digital leads are being asked to assess AI vendors against business cases that have not been independently validated. A vendor's model is only as useful as the departmental data it runs on. Testing the vendor against the actual data environment it will face, not against a demo, is the question worth asking first.
Readiness before procurement. The cheapest intervention in any AI programme is a scoping pass that tells the SRO what the department's data currently supports and what it does not. That work is almost always done after contract award, when it should be done before. The business case that survives a scrutiny board is the one built on a defensible baseline, not on vendor promises.
ISO 55000 as the governance starting point. ISO 55000 is the international standard for asset management. Most AI governance frameworks start from the model outwards; ISO 55000 starts from the asset outwards. That difference of starting point is material. Correctly applied, it provides a governance structure for AI that is defensible at Permanent Secretary level, under NAO review, and in front of a Parliamentary committee. The mapping itself is specialist work and is where most departments would benefit from outside help.
Why the AI governance gap has a shape
The IBM Security Cost of a Data Breach Report 2025 put numbers on this. Sixty-three per cent of breached organisations had no AI governance policy, or were still developing one. Ninety-seven per cent of organisations involved in an AI-related breach reported no AI access controls. Shadow AI adds an average of $670,000 to the cost of a breach. Central government is not outside this trend.
The Cyber Security Breaches Survey 2025 found that only fourteen per cent of UK businesses reviewed the cyber risk of their immediate suppliers in the last year. For departments, where the supply chain is structural, that is a material risk. The Cyber Security and Resilience Bill, progressing through Parliament in this session, will make supply chain security a legal obligation at board level.
SC clearance and the data work itself
Offshore delivery models, standard among the largest consulting firms, typically carry the data work itself (labelling, cleansing, integration, enrichment) on a global capability. For central government work at SC or Secret, that is precisely the layer that cannot leave the boundary. The data that trains, tests and assures a departmental model is often the same data that ICO, CDDO and NAO ask to be provenance-traceable and handling-caveated at source. Offshore data work breaks that chain before the model is built.
The distinct capability for departmental AI is not the framework route. It is whether the data work is performed on-shore by cleared practitioners.
The continuous layer: Data Governance as a Service
Departmental data does not become defensible once and stay defensible. Platform estates change. Suppliers rotate. Classification logic erodes. Criticality ratings go stale. Scrutiny cycles, NAO reviews, PAC hearings and ICO interventions are continuous, not one-off.
Data Governance as a Service (DGaaS) is Brainwave Asset Intelligence's cross-sector model for that continuous layer: on-shore, practitioner-led governance that detects duplicates, degradation and supply-chain integration gaps in the departmental data record between scrutiny points rather than at them. The full treatment, applied consistently across asset-intensive sectors, sits in the DGaaS anchor on this page.
Foundations before automation
Central government's ambition for AI is being set against the pattern the NAO has documented over two decades. Closing that pattern begins lower down the stack than the current conversation usually starts: before the vendor, before the business case, at the departmental data record itself. Parliament, the ICO and the NAO are each asking a version of the same question, about a record that, in most departments, was never built to answer it.
Data readiness is where the answer starts. Foundations before automation.
Key takeaways
- £14 billion of annual spend has not closed the pattern of poor progress on large-scale digital transformation. AI will not either, unless the starting point changes.
- Policy is ahead of departmental practice. The CDDO framework, GDS Playbook and ICO strategy assume data foundations most departments do not yet have.
- Testing AI vendors against the actual departmental data environment, before contract award, is the single highest-leverage intervention available to an SRO.
- ISO 55000 is a defensible governance framework for AI, not only for asset management.
- SC-cleared, on-shore delivery of the data work itself is the capability that matters, not the framework route.
Sources: National Audit Office, Government's approach to technology suppliers, HC 543, 16 January 2025. Cabinet Office / DSIT, AI Opportunities Action Plan: One Year On Progress Update, January 2026. DSIT and Government Digital Service, Digital and Data Benefits Framework, 9 April 2026 (savings figures quoted on the GOV.UK framework page). HM Treasury Green Book. Information Commissioner's Office, Regulating AI: the ICO's strategic approach, 2025; ICO consultation on draft guidance about automated decision-making and profiling, March 2026. IBM Security, Cost of a Data Breach Report 2025. UK Government, Cyber Security Breaches Survey 2025. Verified 20 April 2026.