Government AI governance is becoming operational architecture
The Ministry of Housing, Communities and Local Government has created a shared AI Gateway for departmental digital services.
The platform gives teams a consistent route to approved AI technologies. It centralises security controls, authentication, monitoring, auditability and cost visibility while supporting approximately 20 models through a provider-agnostic interface.
This is an important example of AI governance becoming operational architecture.
Instead of asking each team to create its own model integrations and controls, MHCLG has established a reusable departmental route. Applications running across different cloud environments can access approved capabilities through a common platform.
As AI becomes more deeply embedded in public services, this architecture also reveals the next control question: once an approved model proposes a consequential action, what determines whether that action may proceed?
Model access and action authority are different decisions
An AI Gateway can establish that a service is permitted to use a particular model.
It can authenticate the requesting application, restrict available providers, apply technical controls and record consumption. These are essential functions.
The resulting model output may still propose an action outside the application's authority.
Consider an illustrative public-sector service that reviews property records and maintenance information. It identifies what appears to be duplicate work and proposes cancelling a scheduled building inspection.
The service may have used an approved model, accessed it through the correct gateway, presented valid credentials, complied with its technical access rules and produced a plausible explanation.
None of those conditions independently establishes that the inspection may be cancelled.
The organisation still needs to determine which property is affected, why the inspection was scheduled, whether the records are current, whether cancellation falls within delegated authority and whether specialist review is required.
The model has supplied intelligence. The proposed operational change requires authority.
Provider choice should not change organisational authority
MHCLG has deliberately designed its Gateway to support models from multiple providers.
That flexibility has practical value. Departments can avoid tying every service to one supplier and can add capabilities as the market develops.
Organisational authority, however, should remain consistent when the underlying model changes.
If two approved models propose the same consequential action, the relevant limits should not depend solely on which model produced it. The organisation still needs to apply its own rules to the affected asset, person, record or service.
Likewise, changing providers should not silently expand what an application is permitted to do.
A stable action boundary can allow public bodies to benefit from model competition while retaining control over consequential effects.
The useful outcome may be narrower than the proposal
Operational governance needs more options than accepting or rejecting an entire AI-generated proposal.
In the inspection example, the organisation might allow an administrative correction that does not alter the inspection; deny cancellation because the application lacks that authority; modify the proposal so the suspected duplicate is flagged without cancelling either record; step up the decision to an authorised building-safety officer; or stop the line because the property or inspection status cannot be established reliably.
Stopping the line here would prevent the proposed cancellation from becoming effective. It would not require the model, AI Gateway or unrelated departmental services to be switched off.
Other authorised work could continue.
This is an important distinction for distributed public-sector infrastructure: intervention can be specific to an action, agent, execution path or action class.
Evidence must connect access, authority and effect
Centralised model access improves visibility, but a complete operational record may need to connect several distinct events.
It should show which service accessed which model, what information informed the proposal, what action the service requested, which organisational authority applied, what governed result was returned, whether the proposal was changed or escalated and what action ultimately became effective.
An access log can demonstrate that an approved model was called. It does not necessarily establish that a subsequent operational action was properly authorised.
Equally, an authority decision cannot independently prove that the receiving system carried out the action.
PF Systems' relevant proposition is a separate action-level boundary. PF Memory supplies governed context, PF Kernel evaluates the proposed action, and PF Core preserves linked evidence of that evaluation. Evidence from the executing system remains necessary to establish the effective result.
This does not make the underlying AI deterministic or establish regulatory compliance.
Begin alongside the Gateway, without live execution
A suitable first exercise would not alter a departmental service or place PF Systems in control of live public-sector decisions.
A controlled shadow trial could receive copies of representative proposals generated through an existing AI-enabled service. The existing application would continue through its established process, and PF Systems would not execute the proposed actions.
MHCLG's Gateway demonstrates how government can provide reusable, governed access to changing AI technologies.
The next architectural question is equally practical: how does an organisation ensure that access to approved intelligence never becomes unlimited authority to act?
- Can each requested effect be identified precisely?
- Is the appropriate authority available?
- Does missing information lead to intervention?
- Can an excessive proposal be narrowed?
- Does a changed proposal receive a new evaluation?
- Can reviewers reconstruct the decision afterwards?
Sources
Public sources supporting the factual statements in this perspective. Reported statements and company or vendor-reported results are identified in the article.
