Transparency makes AI deployment visible
The UK has made a significant part of public-sector AI visible. As of 17 August 2026, the government's searchable collection contains 142 Algorithmic Transparency Recording Standard records. They cover organisations ranging from central government and local authorities to the NHS and police, and can be filtered by capability, deployment phase, function and region. Recent entries include systems supporting contact-centre staff, investigations and education.
This is more than a list of technology projects. It is an emerging map of where algorithmic systems are entering public services—and of the governance questions that follow them.
The Algorithmic Transparency Recording Standard, or ATRS, is designed to explain how and why public bodies use algorithmic tools. Its records can identify the responsible organisation, intended purpose, deployment context, external suppliers, human oversight, relevant data, risks and mitigations. Publication is mandatory for qualifying central-government tools in beta, pilot or production, subject to defined exemptions for matters such as security, privacy and intellectual property.
Responsible AI starts with basic visibility. Citizens, public servants and suppliers need to understand what system exists, why it is being used, who owns it, what public function it affects, where human judgement remains and which risks have been considered.
A system record and an action record answer different questions
ATRS is principally a system-level transparency mechanism. It is not presented as a live, per-action control system or transactional evidence log. That distinction is not a criticism. These are different governance functions.
A transparency record might explain that an AI-assisted service categorises correspondence, supports an investigator or flags an application for review. When that system processes a particular case, a second set of operational questions arises.
The public register explains the deployment. Event-level evidence explains the event. Organisations will increasingly need both.
- What did the system propose on this occasion?
- What information was available to it—and who or what requested the action?
- Which authority applied, and was the proposal permitted, changed, escalated or refused?
- What actually happened afterwards, and can the governed evaluation be reconstructed?
Agentic AI raises the importance of the action boundary
The distinction becomes more important when AI moves from producing information to initiating actions. An assistant drafting a case summary, an agent proposing a change to a citizen's record and an agent attempting to release a payment may use similarly capable AI, but their operational consequences are different.
Review before use may be sufficient for a draft. A record change may require an authorised person to confirm the exact amendment. A payment or consequential notification might need financial limits, separation of duties or an immediate refusal if essential conditions are absent.
Human in the loop is therefore not a complete control design by itself. An organisation must define which actions require human involvement, when that involvement occurs, what the approver receives, whether the proposal may be changed, what happens when no authorised person is available and how the decision and resulting action are evidenced.
The UK Government's AI Playbook stresses meaningful human control, lifecycle management, testing, monitoring and auditability. It also cautions against relying on AI alone for high-risk or high-impact applications.
International work is moving in a similar direction. In February 2026, the US National Institute of Standards and Technology highlighted identification, authorisation, auditing and non-repudiation as important questions for software and AI agents. NIST has separately described traceability as depending on the ability to reconstruct an agent's decisions, tool use and supporting evidence.
These sources do not prescribe PF Systems’ architecture. They do reinforce the operational problem: capable agents need explicit authority boundaries and usable evidence.
Governance should sit where a proposal becomes an action
PF Systems’ interpretation is that governance must exist at the point where an AI proposal is about to become consequential. This is the action boundary.
At that boundary, a governed system should be able to produce a proportionate outcome: Allow an authorised action; Deny an action outside its authority; Modify the proposal to an authorised form; Step Up to an appropriate human or additional authority; or Stop the Line when operation should not continue.
This is different from trying to make the underlying probabilistic AI deterministic. The model may still generate uncertain or variable outputs. The governance layer addresses whether a particular proposed action is permitted in its context and what evidence should remain.
PF OS separates these responsibilities. PF Memory knows: it manages governed knowledge and context. PF Core proves: it preserves linked evidence, lineage and the material needed to trace, check and deterministically replay the governed evaluation. PF Kernel decides: it applies the organisation's authority to the proposed action.
ClientBridge can connect an existing system without acquiring PF Kernel's decision authority. PF Trace can present the resulting evidence without manufacturing it.
This separation is intended to let organisations add proportionate governance without requiring every existing model, data platform or operational system to be replaced. It is a forward-looking architectural proposition—not a claim of certification, regulatory compliance or guaranteed safety.
The practical next step is observation before actuation
For an organisation exploring agentic AI, the first useful test is not an immediate production deployment. A controlled shadow pilot can observe proposed actions without allowing the AI to actuate them.
It can help identify which proposed actions are genuinely consequential, which policies can be expressed clearly, how often an action would be allowed, changed or escalated, what an operator needs to see and whether the evidence is sufficient to reconstruct the governed evaluation.
This produces evidence about the proposed operating model while keeping live action outside the pilot boundary. Any subsequent production use remains a separate decision requiring appropriate technical, security, legal, operational and independent-assurance work.
Britain's public AI register makes systems visible. The next stage of trustworthy adoption will require organisations to make authority equally clear before an AI action becomes consequential—and to preserve evidence of what happened afterwards.
Transparency can show where AI is. Governance must show what it was allowed to do.
Sources
Public sources supporting the factual statements in this perspective. Reported statements and company or vendor-reported results are identified in the article.
- GOV.UK — Find out how algorithmic tools are used in public organisations — accessed 17 August 2026
- GOV.UK — ATRS mandatory scope and exemptions policy — 17 December 2024
- GOV.UK — Artificial Intelligence Playbook for the UK Government — 10 February 2025
- NIST — Identity and authority of software agents — 5 February 2026
- NIST — Building measurement probes into agentic AI ecosystems — 7 April 2026
