Public sector
AI for the UK public sector, through G-Cloud via BAPRO
Technical detail for engineering leads
How buying works
G-Cloud, via BAPRO.
G-Cloud is a government framework agreement: a catalogue through which public bodies buy cloud services, including hosting, software and cloud support, from suppliers already on the agreement. It is run by the Government Commercial Agency, which is what the Crown Commercial Service became on 1 April 2026 [1].
It is open to central government, devolved administrations, health, education, local authorities, blue-light services, charities and British overseas territories [1]. G-Cloud 15 started on 6 August 2026 and runs for four years, reopening after 18 months and again after 36 months; its current end date is listed as 5 February 2028 [1]. A buyer can award directly for a straightforward requirement, or run a competition for a larger or more complex one [1].
G-Cloud covers cloud services and cloud support, not the provision of staff or interims. The Government Commercial Agency points buyers to other agreements for contingent labour, non-cloud consultancy and bespoke design and development [1].
Public-sector buyers can work with 1AYM through G-Cloud via our partner BAPRO. BAPRO is the delivery partner and 1AYM is the AI partner, across everything 1AYM offers. 1AYM does not hold a G-Cloud listing in its own name: the framework place is BAPRO's, so a G-Cloud search for 1AYM will not find it. BAPRO holds a G-Cloud 15 place under Lot 3, cloud support.
The first step is a short call to work out whether AI is the right tool for the service in question and what the first piece of work should be. Which of that work goes through BAPRO's G-Cloud services, and how anything outside G-Cloud is contracted, is then agreed with BAPRO and your commercial team.
Bring your commercial colleagues in at the start. The Government AI Playbook's eighth principle is to work with commercial colleagues from the start, and its buying guidance says to discuss partners, pricing, products and services with them [2].
What we do for public bodies
The same work we offer everyone.
Small fixed-scope pieces of work as well as larger builds, each ending with something written down and handed over. Not all of it is bought through G-Cloud: G-Cloud does not cover the provision of staff, non-cloud consultancy or bespoke development [1], so the route for each piece of work is settled with BAPRO and your commercial team at the start.
- Strategy and discovery
- Where AI would help a service and what it would take: the two or three workflows worth building, ranked against value, risk and cost, with the architecture, a delivery roadmap and an investment case. Fixed scope, typically two to four weeks. AI Opportunity & Feasibility Sprint
- Implementation
- One real workflow, end to end, in your systems and against your data, then taken to production with identity, monitoring, deterministic checks and human approval sized to the risk. Enterprise AI Platform & Agentic Workflows
- Enablement
- For digital and engineering teams rolling out Codex or Claude Code: guardrails in the repository and in the build pipeline, so AI-assisted code reaches production the same way every other change does. Enablement also runs through every other engagement, so the capability stays when we leave. AI Engineering Transformation
- Governance
- Governance built as controls rather than written as a policy: use-case approval, data-sensitivity classification, least-privilege access, audit logging and staged rollout with monitoring behind it. AI governance implementation
- Associate teams
- Engineers placed on a headcount basis inside your own programme, directed by your team day to day, on a contract from three months. The team scales with the contract, and every engineer meets the same hiring standard. G-Cloud does not cover the provision of staff [1], so an associate team is not bought through G-Cloud; how it is contracted is agreed with BAPRO. Embedded Engineers on Contract
The UK guidance
What public-sector AI work has to meet.
Five pieces of UK guidance shape how a public body uses AI. For each one: what it asks, and how we build so the evidence it needs exists by the time you need it. Read on 29 September 2026. This is a reading of published guidance, not legal advice, and your organisation's own policies and assurance still apply.
Government AI Playbook
Government Digital Service, February 2025
What it asks. Ten principles for civil servants and people working in government organisations, among them knowing how to use AI securely, meaningful human control at the right stages, managing the full AI life cycle and using the right tool for the job [2].
How we build to it. Human approval is built in where the risk warrants it, evaluation runs whenever a prompt or a model changes, and model choice is made per workload and written down, so the life cycle has an owner and a record. [2]
Algorithmic Transparency Recording Standard
Government Digital Service
What it asks. A standard way for public sector organisations to publish how and why they use algorithmic tools. It is mandatory for government departments and for arm's-length bodies that deliver public or frontline services or deal directly with the public [3].
How we build to it. The architecture, the data the system uses, the human oversight and the model and vendor decisions are written down and dated as the work runs, so an ATRS record draws on documents that already exist. [3]
Technology Code of Practice
Government Digital Service and the Central Digital and Data Office, July 2025
What it asks. Thirteen criteria for designing, building and buying government technology, used in Cabinet Office spend control. They include defining user needs, making things secure, making privacy integral, integrating and adapting existing technology, and defining a purchasing strategy [4].
How we build to it. Discovery starts from the service and the people who run it, the build goes into the systems you already have, and everything we build is documented and handed over for your team to maintain. [4]
ICO guidance on AI and data protection
Information Commissioner's Office, under review after the Data (Use and Access) Act 2025
What it asks. How UK data protection law applies to AI: accountability and data protection impact assessments, lawfulness, fairness, transparency, accuracy, security, data minimisation and individual rights [5].
How we build to it. We work to UK GDPR and the Data Protection Act 2018. An AI system sees only what the user is already entitled to see, and we document the data flows your impact assessment needs. [5]
Guidelines for secure AI system development
National Cyber Security Centre, November 2023
What it asks. Security across four stages of an AI system's life: secure design, secure development, secure deployment, and secure operation and maintenance, including logging, monitoring and update management [6].
How we build to it. Least-privilege, default-deny access from the design stage; audit logging that records refusals as well as answers; release control, monitoring and incident handling in production. [6]
For engineering and technical leads
For engineering and technical leads: data, residency, evaluation and audit
Data handling
Access is least-privilege and default-deny. Context is permission-aware, so a model is only given what the requesting user is already entitled to see. Data sensitivity is classified at use-case approval, before anything is built.
Residency
Where data must stay in a region, we architect for it: one production estate we run was replatformed onto Postgres 16 in Google Cloud's Doha region (me-central1) to meet Gulf data-residency requirements. For UK storage, vendor terms differ by plan. On the published terms, ChatGPT Enterprise offers UK storage at rest for new workspaces, though in-region inference is offered only in Europe, the US and the UAE. Anthropic states that data on its commercial products is stored in the US. The region is a design input, decided with you and written down.
Evaluation
Regression suites run in CI whenever a prompt or a model changes, so a quality drop is caught before users find it. Deterministic checks sit on consequential outputs, and low-confidence cases route to human review. On one production estate the CI gates include fairness checks broken down by the candidate's first language.
Audit records
The audit trail is a by-product of the gates on consequential actions, and it records refusals as well as answers. Model and vendor decisions are dated, and the handover includes the documentation your team needs to run and change the system.
The plan terms above are cited, with the date they were checked, in our comparison of the ChatGPT and Claude business plans.
Frequently asked questions
Can we buy from 1AYM through G-Cloud?
Yes, via our partner BAPRO. 1AYM does not hold a G-Cloud listing in its own name: the framework place is BAPRO's, so a G-Cloud search for 1AYM will not find it. BAPRO holds a G-Cloud 15 place under Lot 3, cloud support. BAPRO is the delivery partner and 1AYM is the AI partner, across everything 1AYM offers. G-Cloud covers cloud services and cloud support, not the provision of staff, so which pieces of work go through it is agreed with BAPRO and your commercial team at the start.
Who does the AI work?
1AYM does: the AI strategy, architecture, engineering, governance and enablement. Every 1AYM engineer is either certified on the platforms we build on or has shipped inside a top-tier engineering organisation, and you meet the engineers before you sign.
Which public bodies can buy through G-Cloud?
The Government Commercial Agency lists central government, charities, education, health, local authorities, blue-light services (police, fire, ambulance, search and rescue), devolved administrations and British overseas territories (read 29 September 2026).
Can we start with a small piece of work?
Yes. Most work starts as a fixed-scope statement of work with defined outputs and a defined price, such as a two-to-four week AI Opportunity & Feasibility Sprint or a first production slice against one real workflow. Larger builds and associate teams are there when the work calls for them.
Which AI models do you use?
Whichever the workload argues for, across OpenAI, Anthropic, Gemini and open-source. The Government AI Playbook's sixth principle asks the same: use the right tool for the job. 1AYM is an OpenAI Select Partner; that is a company status, not a sales agreement, and model choice still comes from evidence on the workload.
Do you hold ISO or SOC certification?
No. We work to UK GDPR and the Data Protection Act 2018, plus whatever your sector adds, and we architect for data residency where a region is a requirement. We hold no ISO or SOC certification, and we do not imply one.
Sources
- [1]Government Commercial Agency, G-Cloud 15 (RM1557.15): who can buy, status, dates, lots and buying routes (read 29 September 2026)
- [2]Government Digital Service, AI Playbook for the UK Government, 10 February 2025 (read 29 September 2026)
- [3]Government Digital Service, Algorithmic Transparency Recording Standard hub, updated 8 May 2025 (read 29 September 2026)
- [4]Government Digital Service and Central Digital and Data Office, The Technology Code of Practice, updated 7 July 2025 (read 29 September 2026)
- [5]Information Commissioner's Office, Guidance on AI and data protection, updated 15 March 2023 and under review (read 29 September 2026)
- [6]National Cyber Security Centre, Guidelines for secure AI system development, 27 November 2023 (read 29 September 2026)
Start with one service.
Half an hour is enough to tell you whether AI is the right tool for the service you have in mind, what it would take, and how buying it through BAPRO would work. We will say plainly when the answer is that you do not need us.
Last reviewed · 1AYM