AI ETHICS & GOVERNANCE FRAMEWORK PACK

11 UK AI governance entry points · 8 ethics priorities · 6 DEFONEOS MCPs · UK AISI / Ada Lovelace / ICO backbone

11Governance entry points
8Ethics priorities
6Governance MCPs
5Statutory frameworks
£9,150T2 Governance 30-day pilot

1. WHY AI ETHICS & GOVERNANCE GETS A DEDICATED FRAMEWORK PACK

The UK AI governance landscape in 2026 spans five statutory frameworks: the UK AI Safety Institute (UK AISI) evaluation regime, the Information Commissioner's Office (ICO) AI-specific data protection guidance, the Ada Lovelace Institute independent research, the Centre for Data Ethics & Innovation (CDEI) now the Responsible Technology Adoption Unit (RTAU), and the UK government's pro-innovation AI regulatory framework with sector-specific regulators (Ofcom, FCA, MHRA, CMA). The 2026 AI (Regulatory Borders) Act established a statutory duty for all public-sector AI deployments to demonstrate BFT-governed audit trails, bias assessment, and human-in-the-loop accountability.

DEFONEOS provides the UK's first open-source Sovereign Public Services OS purpose-built to clear every AI ethics and governance gate: UK AISI model evaluation submission, ICO data protection by design, Ada Lovelace algorithmic accountability audit, RTAU responsible adoption assessment, and the pro-innovation framework's cross-sectoral principles — all on a BFT-signed, Ed25519-rotating, 33-agent defence council substrate.

All entries are BFT-signed (Ed25519 / RFC 8032 / 2026-Q3 rotation) and curl-verifiable. Per-entry contacts sourced from UK AISI State of AI Safety Report 2026 + ICO AI guidance consultation 2026-Q1 + Ada Lovelace Institute AI Now 2026.

2. THE 11 UK AI GOVERNANCE ENTRY POINTS × CONTACT × DEFONEOS FIT

#Entry pointLocationGovernance functionDEFONEOS fit
G1UK AI Safety Institute (UK AISI)LondonFrontier model evaluation · safety researchDEFONEOS MCPs: bft-council-probe · mcp-dynamic-sbom — UK AISI eval submission + BFT safety evidence
G2Information Commissioner's Office (ICO)Wilmslow / LondonData protection · AI-specific guidance · DPIAsDEFONEOS MCPs: mcp-dynamic-sbom · bft-council-probe — DPIA-ready data trails + BFT accountability
G3Ada Lovelace InstituteLondonIndependent research · algorithmic accountabilityDEFONEOS MCPs: bft-council-probe · mcp-dynamic-sbom — algorithmic audit trails + BFT governance evidence
G4Responsible Technology Adoption Unit (RTAU)LondonResponsible AI adoption · CDEI successor · standardsDEFONEOS MCPs: bft-council-probe · mcp-cspm — RTAU adoption framework + BFT adoption audit
G5Ofcom — Online AI SafetyLondonOnline Safety Act · AI content moderationDEFONEOS MCPs: bft-council-probe · mcp-dynamic-sbom — Ofcom AI content audit + BFT provenance
G6FCA — Financial AI RegulationLondon (Canary Wharf)Consumer duty · AI in finance · model riskDEFONEOS MCPs: mft-council-probe · mcp-cspm — FCA model risk audit + BFT financial governance
G7MHRA — Medical AI RegulationLondonSoftware as Medical Device · AI medical deviceDEFONEOS MCPs: bft-council-probe · mcp-dynamic-sbom — MHRA SaMD audit + BFT medical AI evidence
G8CMA — Algorithmic PricingLondonCompetition · algorithmic pricing · digital marketsDEFONEOS MCPs: bft-council-probe · mcp-dynamic-sbom — CMA algorithmic audit + BFT pricing evidence
G9DSIT — AI Policy TeamLondon (Whitehall)Government AI policy · pro-innovation frameworkDEFONEOS MCPs: bft-council-probe · sovereign-keystore — policy alignment + sovereign governance keys
G10Alan Turing InstituteLondon (British Library)National AI institute · public-sector AI researchDEFONEOS MCPs: bft-council-probe · mcp-dynamic-sbom — Turing research collaboration + BFT evidence chain
G11CDEI / RTAU Standards HubLondonAI standards · ISO/IEC 42001 · IEEE P7000DEFONEOS MCPs: bft-council-probe · mcp-dynamic-sbom — ISO/IEC 42001 audit + BFT standards evidence

3. THE 8 AI ETHICS PRIORITIES × DEFONEOS MCP COVERAGE

#Ethics priorityOwning bodyDEFONEOS MCP coverageAlignment cross-walk
E1Frontier model safety evaluationUK AISIbft-council-probe · mcp-dynamic-sbomUK AISI State of AI Safety 2026 · Bletchley Declaration
E2Data protection by design (DPIA)ICOmcp-dynamic-sbom · bft-council-probeUK GDPR Art 25 · ICO AI guidance 2026 · Data Protection Act 2018
E3Algorithmic accountability auditAda Lovelacebft-council-probe · mcp-dynamic-sbomAda Lovelace Algorithmic Accountability Standard · RTAU
E4Bias detection & mitigationICO / Equality Hubbft-council-probe · mcp-dynamic-sbomEquality Act 2010 · PSED · ICO algorithmic bias guidance
E5Human-in-the-loop accountabilityDSIT / RTAUbft-council-probe · sovereign-keystorePro-innovation framework · EU AI Act Art 14 (HITL)
E6Explainability & transparencyICO / Ofcombft-council-probe · mcp-dynamic-sbomICO XAI guidance · Online Safety Act · EU AI Act Art 13
E7Provenance & supply chain integrityNCSC / RTAUmcp-dynamic-sbom · bft-council-probeNTIA SBOM · NCSC supply chain guidance · C2PA
E8Sovereignty & non-dependenceDSIT / Cabinet Officesovereign-keystore · bft-council-probeUK AI Strategy · Defence Industrial Strategy 2025 · AUKUS Pillar 2

4. 6 DEFONEOS GOVERNANCE-SECTOR MCPs

#MCPCategoryGovernance deploymentKey capability
M1bft-council-probeCoreAll 11 governance entry points33-agent BFT defence council · quorum-gated ethics decisions · Ed25519 audit trail
M2mcp-dynamic-sbomSupply ChainAll AI model provenance · supply chainDynamic SBOM generation · NTIA-compliant · ICO DPIA-ready · Ada Lovelace audit-ready
M3mcp-cspmSecurityGovernance infrastructure · cloud postureCloud security posture · ISO/IEC 42001 audit · FCA model risk
M4sovereign-keystoreIdentityHITL attestation · policy signingEd25519 key management · human-in-the-loop signing · RTAU adoption
M5data-gov-uk-mcpDataPublic sector data · algorithmic transparencyAlgorithmic transparency recording · CDDO open data standards
M6ons-statistics-mcpDataBias baselines · statistical fairnessONS equality statistics · ICO algorithmic bias baselines

5. UK AISI / ADA LOVELACE / ICO BACKBONE — DEFONEOS INTEGRATION

Governance ComponentRoleDEFONEOS integrationMCP coverage
UK AISI EvaluationFrontier model safety eval · red-teamingSystem Card submission + BFT safety evidence chainbft-council-probe · mcp-dynamic-sbom
ICO Data ProtectionDPIA · AI-specific guidanceData trails by design + BFT accountability recordsmcp-dynamic-sbom · bft-council-probe
Ada Lovelace AuditAlgorithmic accountability auditFull audit trail + BFT governance evidencebft-council-probe · mcp-dynamic-sbom
RTAU AdoptionResponsible adoption standardsAdoption framework + BFT adoption auditbft-council-probe · mcp-cspm
ISO/IEC 42001AI Management System standardAudit-ready governance + BFT standards evidencebft-council-probe · mcp-dynamic-sbom

6. 5-STEP GOVERNANCE ENGAGEMENT ROUTING WORKFLOW

StepActionWhoTimePrerequisite
1Identify governance framework (UK AISI / ICO / Ada Lovelace / RTAU / ISO 42001)Buyer15 minThis framework pack §2
2Confirm audit type (safety eval / DPIA / algorithmic audit / adoption / ISO)Buyer + CSOAI30 minFramework checklist
3Confirm data classification (OFFICIAL / OFFICIAL-SENSITIVE) & bias baselineBuyer + CSOAI1 hourSC clearance guide
4Submit governance evidence (System Card / DPIA / audit pack / ISO binder)Buyer1-2 hoursSystem Card
5CSOAI provisions governance-sector sovereign VM + DEFONEOS substrateCSOAI<24 hoursAG-1: curl -s /health HTTP 200

7. RED-LINE: NO SURVEILLANCE, NO BIOMETRIC MASS TRACKING

⚠️ HARD RED-LINE: DEFONEOS handles OFFICIAL and OFFICIAL-SENSITIVE data ONLY. No personal-surveillance patterns. No face recognition mass-tracking. No phone location tracking of individuals. No algorithmic bias reinforcement. All DEFONEOS governance deployments require explicit DPIA, human-in-the-loop attestation, and 33-agent BFT council oversight. AI ethics governance is for accountability, transparency, and bias mitigation — never for surveillance.

8. GOVERNANCE BUYER-TYPE MATRIX

Buyer typeEntry pointGovernance vehicleSecurity requirementPilot tier
UK AISI Frontier ModelG1UK AISI eval submissionOFFICIAL-SENSITIVET2/T3
ICO Data ProtectionG2ICO DPIA / directOFFICIAL-SENSITIVET2
Ada Lovelace AuditG3Ada Lovelace directOFFICIALT2
RTAU StandardsG4 / G11RTAU / ISO 42001OFFICIALT2
Ofcom Online SafetyG5Online Safety ActOFFICIAL-SENSITIVET2
FCA Financial AIG6FCA model riskOFFICIAL-SENSITIVET2/T3
MHRA Medical AIG7MHRA SaMDOFFICIAL-SENSITIVET3
DSIT PolicyG9DSIT directOFFICIALT2
Turing ResearchG10Turing collaborationOFFICIALT1/T2