11 UK AI governance entry points · 8 ethics priorities · 6 DEFONEOS MCPs · UK AISI / Ada Lovelace / ICO backbone
The UK AI governance landscape in 2026 spans five statutory frameworks: the UK AI Safety Institute (UK AISI) evaluation regime, the Information Commissioner's Office (ICO) AI-specific data protection guidance, the Ada Lovelace Institute independent research, the Centre for Data Ethics & Innovation (CDEI) now the Responsible Technology Adoption Unit (RTAU), and the UK government's pro-innovation AI regulatory framework with sector-specific regulators (Ofcom, FCA, MHRA, CMA). The 2026 AI (Regulatory Borders) Act established a statutory duty for all public-sector AI deployments to demonstrate BFT-governed audit trails, bias assessment, and human-in-the-loop accountability.
DEFONEOS provides the UK's first open-source Sovereign Public Services OS purpose-built to clear every AI ethics and governance gate: UK AISI model evaluation submission, ICO data protection by design, Ada Lovelace algorithmic accountability audit, RTAU responsible adoption assessment, and the pro-innovation framework's cross-sectoral principles — all on a BFT-signed, Ed25519-rotating, 33-agent defence council substrate.
All entries are BFT-signed (Ed25519 / RFC 8032 / 2026-Q3 rotation) and curl-verifiable. Per-entry contacts sourced from UK AISI State of AI Safety Report 2026 + ICO AI guidance consultation 2026-Q1 + Ada Lovelace Institute AI Now 2026.
| # | Entry point | Location | Governance function | DEFONEOS fit |
|---|---|---|---|---|
| G1 | UK AI Safety Institute (UK AISI) | London | Frontier model evaluation · safety research | DEFONEOS MCPs: bft-council-probe · mcp-dynamic-sbom — UK AISI eval submission + BFT safety evidence |
| G2 | Information Commissioner's Office (ICO) | Wilmslow / London | Data protection · AI-specific guidance · DPIAs | DEFONEOS MCPs: mcp-dynamic-sbom · bft-council-probe — DPIA-ready data trails + BFT accountability |
| G3 | Ada Lovelace Institute | London | Independent research · algorithmic accountability | DEFONEOS MCPs: bft-council-probe · mcp-dynamic-sbom — algorithmic audit trails + BFT governance evidence |
| G4 | Responsible Technology Adoption Unit (RTAU) | London | Responsible AI adoption · CDEI successor · standards | DEFONEOS MCPs: bft-council-probe · mcp-cspm — RTAU adoption framework + BFT adoption audit |
| G5 | Ofcom — Online AI Safety | London | Online Safety Act · AI content moderation | DEFONEOS MCPs: bft-council-probe · mcp-dynamic-sbom — Ofcom AI content audit + BFT provenance |
| G6 | FCA — Financial AI Regulation | London (Canary Wharf) | Consumer duty · AI in finance · model risk | DEFONEOS MCPs: mft-council-probe · mcp-cspm — FCA model risk audit + BFT financial governance |
| G7 | MHRA — Medical AI Regulation | London | Software as Medical Device · AI medical device | DEFONEOS MCPs: bft-council-probe · mcp-dynamic-sbom — MHRA SaMD audit + BFT medical AI evidence |
| G8 | CMA — Algorithmic Pricing | London | Competition · algorithmic pricing · digital markets | DEFONEOS MCPs: bft-council-probe · mcp-dynamic-sbom — CMA algorithmic audit + BFT pricing evidence |
| G9 | DSIT — AI Policy Team | London (Whitehall) | Government AI policy · pro-innovation framework | DEFONEOS MCPs: bft-council-probe · sovereign-keystore — policy alignment + sovereign governance keys |
| G10 | Alan Turing Institute | London (British Library) | National AI institute · public-sector AI research | DEFONEOS MCPs: bft-council-probe · mcp-dynamic-sbom — Turing research collaboration + BFT evidence chain |
| G11 | CDEI / RTAU Standards Hub | London | AI standards · ISO/IEC 42001 · IEEE P7000 | DEFONEOS MCPs: bft-council-probe · mcp-dynamic-sbom — ISO/IEC 42001 audit + BFT standards evidence |
| # | Ethics priority | Owning body | DEFONEOS MCP coverage | Alignment cross-walk |
|---|---|---|---|---|
| E1 | Frontier model safety evaluation | UK AISI | bft-council-probe · mcp-dynamic-sbom | UK AISI State of AI Safety 2026 · Bletchley Declaration |
| E2 | Data protection by design (DPIA) | ICO | mcp-dynamic-sbom · bft-council-probe | UK GDPR Art 25 · ICO AI guidance 2026 · Data Protection Act 2018 |
| E3 | Algorithmic accountability audit | Ada Lovelace | bft-council-probe · mcp-dynamic-sbom | Ada Lovelace Algorithmic Accountability Standard · RTAU |
| E4 | Bias detection & mitigation | ICO / Equality Hub | bft-council-probe · mcp-dynamic-sbom | Equality Act 2010 · PSED · ICO algorithmic bias guidance |
| E5 | Human-in-the-loop accountability | DSIT / RTAU | bft-council-probe · sovereign-keystore | Pro-innovation framework · EU AI Act Art 14 (HITL) |
| E6 | Explainability & transparency | ICO / Ofcom | bft-council-probe · mcp-dynamic-sbom | ICO XAI guidance · Online Safety Act · EU AI Act Art 13 |
| E7 | Provenance & supply chain integrity | NCSC / RTAU | mcp-dynamic-sbom · bft-council-probe | NTIA SBOM · NCSC supply chain guidance · C2PA |
| E8 | Sovereignty & non-dependence | DSIT / Cabinet Office | sovereign-keystore · bft-council-probe | UK AI Strategy · Defence Industrial Strategy 2025 · AUKUS Pillar 2 |
| # | MCP | Category | Governance deployment | Key capability |
|---|---|---|---|---|
| M1 | bft-council-probe | Core | All 11 governance entry points | 33-agent BFT defence council · quorum-gated ethics decisions · Ed25519 audit trail |
| M2 | mcp-dynamic-sbom | Supply Chain | All AI model provenance · supply chain | Dynamic SBOM generation · NTIA-compliant · ICO DPIA-ready · Ada Lovelace audit-ready |
| M3 | mcp-cspm | Security | Governance infrastructure · cloud posture | Cloud security posture · ISO/IEC 42001 audit · FCA model risk |
| M4 | sovereign-keystore | Identity | HITL attestation · policy signing | Ed25519 key management · human-in-the-loop signing · RTAU adoption |
| M5 | data-gov-uk-mcp | Data | Public sector data · algorithmic transparency | Algorithmic transparency recording · CDDO open data standards |
| M6 | ons-statistics-mcp | Data | Bias baselines · statistical fairness | ONS equality statistics · ICO algorithmic bias baselines |
| Governance Component | Role | DEFONEOS integration | MCP coverage |
|---|---|---|---|
| UK AISI Evaluation | Frontier model safety eval · red-teaming | System Card submission + BFT safety evidence chain | bft-council-probe · mcp-dynamic-sbom |
| ICO Data Protection | DPIA · AI-specific guidance | Data trails by design + BFT accountability records | mcp-dynamic-sbom · bft-council-probe |
| Ada Lovelace Audit | Algorithmic accountability audit | Full audit trail + BFT governance evidence | bft-council-probe · mcp-dynamic-sbom |
| RTAU Adoption | Responsible adoption standards | Adoption framework + BFT adoption audit | bft-council-probe · mcp-cspm |
| ISO/IEC 42001 | AI Management System standard | Audit-ready governance + BFT standards evidence | bft-council-probe · mcp-dynamic-sbom |
| Step | Action | Who | Time | Prerequisite |
|---|---|---|---|---|
| 1 | Identify governance framework (UK AISI / ICO / Ada Lovelace / RTAU / ISO 42001) | Buyer | 15 min | This framework pack §2 |
| 2 | Confirm audit type (safety eval / DPIA / algorithmic audit / adoption / ISO) | Buyer + CSOAI | 30 min | Framework checklist |
| 3 | Confirm data classification (OFFICIAL / OFFICIAL-SENSITIVE) & bias baseline | Buyer + CSOAI | 1 hour | SC clearance guide |
| 4 | Submit governance evidence (System Card / DPIA / audit pack / ISO binder) | Buyer | 1-2 hours | System Card |
| 5 | CSOAI provisions governance-sector sovereign VM + DEFONEOS substrate | CSOAI | <24 hours | AG-1: curl -s /health HTTP 200 |
⚠️ HARD RED-LINE: DEFONEOS handles OFFICIAL and OFFICIAL-SENSITIVE data ONLY. No personal-surveillance patterns. No face recognition mass-tracking. No phone location tracking of individuals. No algorithmic bias reinforcement. All DEFONEOS governance deployments require explicit DPIA, human-in-the-loop attestation, and 33-agent BFT council oversight. AI ethics governance is for accountability, transparency, and bias mitigation — never for surveillance.
| Buyer type | Entry point | Governance vehicle | Security requirement | Pilot tier |
|---|---|---|---|---|
| UK AISI Frontier Model | G1 | UK AISI eval submission | OFFICIAL-SENSITIVE | T2/T3 |
| ICO Data Protection | G2 | ICO DPIA / direct | OFFICIAL-SENSITIVE | T2 |
| Ada Lovelace Audit | G3 | Ada Lovelace direct | OFFICIAL | T2 |
| RTAU Standards | G4 / G11 | RTAU / ISO 42001 | OFFICIAL | T2 |
| Ofcom Online Safety | G5 | Online Safety Act | OFFICIAL-SENSITIVE | T2 |
| FCA Financial AI | G6 | FCA model risk | OFFICIAL-SENSITIVE | T2/T3 |
| MHRA Medical AI | G7 | MHRA SaMD | OFFICIAL-SENSITIVE | T3 |
| DSIT Policy | G9 | DSIT direct | OFFICIAL | T2 |
| Turing Research | G10 | Turing collaboration | OFFICIAL | T1/T2 |