Most public bodies buy AI from an existing commercial agreement instead of running a fresh tender. Two routes dominate: G-Cloud 15 for cloud and cloud support, which sits under the Procurement Act 2023, and the RM6200 artificial intelligence dynamic purchasing system, which still runs under the 2015 regulations. Define the requirement, search the catalogue, award.
What is a government framework, and how does buying AI through one work?
A framework is a competition that has already happened. The Government Commercial Agency runs an open procurement, admits the suppliers who pass, and publishes what each one offers. Your organisation then calls off a contract from that agreement instead of advertising its own. The agency was Crown Commercial Service until 1 April 2026, so much of the guidance you will find still uses the old name.
The sequence is the same whichever agreement you land on. Write the requirement down before you open any catalogue. Choose the agreement whose published scope actually covers the thing you are buying. Search and filter the admitted suppliers. Check whether that agreement lets you award directly or obliges you to run a further competition. Evaluate against criteria you settled in advance. Award, publish the notices your regime requires, and keep the record of why you chose what you chose.
The order matters more than people expect. Teams who browse first and specify afterwards end up describing the product they liked rather than the problem they have, and that is very hard to defend when a losing supplier asks why.
Which framework fits which kind of AI purchase?
Match the agreement to the thing, not to the word "AI". Most AI purchases are one of four things wearing the same label.
If you are buying a hosted service, a platform, or support to run one, that is cloud, and G-Cloud 15 is the usual home. If you are buying capability delivered to you, meaning discovery work, data engineering, model development or evaluation, the RM6200 artificial intelligence agreement is built for exactly that. If you are buying software licences to run on infrastructure you already own, plus the hardware underneath it, that is neither cloud nor a service, and it usually belongs on a technology products and associated services agreement or a hardware agreement. If what you actually need is people inside your team, Digital Outcomes and Specialists 7, live since 1 April 2026, or Digital Specialists and Programmes (RM6263) fit better than any of the above. If the answer is software on your own estate, on-premise AI for the public sector covers what changes in the requirement.
Getting this wrong is the most common avoidable failure I see. An award outside an agreement's published scope is a direct award with no cover, whatever the paperwork says.
What is on G-Cloud 15?
G-Cloud 15 (RM1557.15) is a catalogue of cloud services with five lots: Lot 1a infrastructure as a service and platform as a service, Lot 1b the same above OFFICIAL (published as AO), Lot 2a infrastructure software, Lot 2b other software as a service, and Lot 3 cloud support services. It runs from 6 August 2026 to 5 February 2028.
Lot 1b is the one AI buyers overlook. If your workload sits above OFFICIAL, that lot exists because the assurance expectations are different, and buying a general OFFICIAL service in the hope of hardening it later is not a plan.
Lot 3 is underused too. Cloud support covers the work around a service: migration, setup, security assessment, ongoing operation. If you are standing up AI capability on infrastructure you control, the operational help often matters more than the model does.
What is the RM6200 Artificial Intelligence agreement?
RM6200 is the agency's artificial intelligence agreement, and structurally it is a dynamic purchasing system rather than a closed framework. That has two consequences worth knowing before you set a timeline.
First, it stays open. Suppliers can apply to join throughout its life, so the supplier list you looked at last year is not the list you will see today. Refresh it before you build a shortlist.
Second, and this is the part that trips buyers up, every contract awarded through a dynamic purchasing system needs a competition among the admitted suppliers in the relevant category. There is no browse-and-award shortcut. RM6200 was established on 3 September 2020 and has been extended to 23 February 2029.
When can you award directly and when must you compete?
On G-Cloud, in principle yes. On RM6200, no. That is the short version, and it catches people out because both sit on the same website and look like the same kind of thing.
G-Cloud permits competitive and non-competitive call-off procedures. You define the requirement, filter the catalogue against it, apply your published criteria, and if one service meets the requirement on those criteria you can award without running a further competition. The audit trail is the entire defence: your requirement, your criteria, your filters, your reasoning, dated and kept.
A dynamic purchasing system works differently. The 2015 regulations require that every supplier admitted to the relevant category gets the chance to tender for each specific contract. You cannot pick one off the list because you already know them.
If you want a direct award and the honest answer is that you cannot have one, plan the competition properly rather than hunting for a justification after the fact. The justification written afterwards is the one that reads like it was written afterwards.
What should the requirement specify about data and hosting?
This is where a framework buy either protects you or quietly does not. The agreement settles the route. It does not settle where your data goes. I have written a longer sovereign AI procurement checklist for buyers if you want the question list on its own.
Specify six things in writing. Where processing physically happens, and who holds the keys. Whether any data leaves your estate, and if so exactly what and to whom. Whether your inputs and outputs can be used to train anyone's model, which should be a plain no. What evidence the system produces about what it did, and, crucially, whether a third party can verify that evidence without the supplier's cooperation. Which actions require a named human to approve them before they take effect. And what happens on exit: can the thing you bought keep running if the supplier stops answering the phone. Hosting location and egress are separate questions, and data residency and sovereignty in government AI tenders is where tender answers usually fall apart.
Check whether a data protection impact assessment is required for the processing you are planning, because for higher risk uses it is a legal obligation rather than good practice, and the ICO publishes guidance on when it applies. If you sit in central government, check whether your tool needs an entry in the Algorithmic Transparency Recording Standard.
I build the Mickai Sovereign Intelligence Operating System, so I have a position here and you should read it as one. SIOS runs on hardware the customer owns, is offline capable, and does not egress data. Every consequential action is sealed in an Open Audit Record under ML-DSA-65, the post-quantum signature scheme NIST published as FIPS 204 in 2024, and an auditor verifies an exported record offline with a public key, using tools that are not ours. That is tamper-evident, not tamper-proof, and the distinction is the whole point: nothing stops a privileged party altering a record, but altering it makes verification fail, which is what an auditor actually needs. Consequential actions wait for a named person to approve them. The platform carries 63 studios, 14 production-ready and 49 in development, across 50 specialised models. Closed beta is open, with one regulated organisation onboarding as a design partner.
None of that means Mickai is on any of these agreements, and I make no such claim. It means you should write the requirement first and let the route follow, because a requirement shaped around a product is a requirement you cannot defend.
I am also not arguing against cloud, or against the companies building the compute and cloud layer. Cloud is the right answer for a great deal of public sector work. The argument is with the assumption that a regulated organisation must rent its intelligence, ship its data offsite, and take a vendor's word for what happened to it.
Which rules apply: the Procurement Act 2023 or the 2015 regulations?
Both, depending on which agreement you call off from. The Procurement Act 2023 has applied to new procurements since 24 February 2025, but agreements established under the Public Contracts Regulations 2015 continue to be governed by those regulations for the rest of their life. The rulebook follows the agreement, not today's date.
So G-Cloud 15 sits under the Procurement Act 2023, while a call-off from RM6200 follows the 2015 regulations. The practical differences are real. The notices and transparency steps are not the same, the vocabulary is not the same (a dynamic purchasing system under the older rules, a dynamic market under the Act), and your internal call-off templates may silently assume one regime.
Ask your commercial team which regime applies before you draft anything. Getting that straight at the start costs an email. Getting it wrong costs the award. For why buyers are asking at all, see sovereign AI for the UK public sector.
Frequently asked questions
Which framework should we use to buy AI?
Match the agreement to what you are buying. Hosted services, platforms and cloud support belong on G-Cloud 15. Capability delivered as work, such as discovery, data engineering or model development, belongs on the RM6200 artificial intelligence agreement. Software licences for infrastructure you already own usually sit on a technology products agreement instead. Check the published scope before shortlisting.
Can we award an AI contract directly, or do we still need to run a tender?
It depends on the agreement. Calling off from a framework means you do not run a fresh open tender, because that competition already happened. G-Cloud permits non-competitive call-offs, so you can define a requirement, filter the catalogue against published criteria and award. RM6200 is a dynamic purchasing system, and the 2015 regulations require every admitted supplier in the category to be invited to tender.
What can we buy through G-Cloud 15?
Cloud services across five lots: 1a infrastructure and platform services, 1b the same above OFFICIAL, 2a infrastructure software, 2b other software as a service, and 3 cloud support. Lot 3 covers migration, setup, security assessment and ongoing operation, which often matters more than the model. It runs from 6 August 2026 to 5 February 2028.
Can we specify on-premise or air-gapped hosting on a framework?
Yes, in your requirement, provided the agreement's scope covers what you are buying and your criteria are proportionate. Hosting location, key custody and data egress are legitimate requirements, not preferences. Be aware that software licensed to run on hardware you own is not a cloud service, so a cloud catalogue may be the wrong route for it.
Who can buy from these agreements?
Public sector bodies listed as eligible buyers on each agreement, which typically includes central government departments and their arm's length bodies, local authorities, education, blue light services, registered charities, the devolved administrations and British overseas territories. Eligibility is set agreement by agreement, so check the published buyer list rather than assuming your organisation qualifies.
Related briefings
Procurement and defence
- AI Disclosure in Public Sector Tenders: What's Required?
- AI Bid Evaluation in Public Procurement: Is It Lawful?
- AI for Procurement Contract Review: Is It Allowed?
- AI Supplier Contract Clauses: A UK Buyer's Checklist
- JSP 936 for AI Suppliers: What the MOD Now Requires
UK AI regulation
- Is There a UK AI Act? How the UK Regulates AI Today
- AI Cyber Security Code of Practice: Who It Applies To
Part of a series of 60 briefings on deploying and governing AI in UK regulated organisations, archived with a DOI at 10.5281/zenodo.22975756.
Evaluating AI for a regulated organisation? Mickai runs on hardware you own, offline. Consequential actions wait for a named person to approve them, and what the AI did is sealed into a signed record an auditor can check without us. Applications for the invitation-only closed beta are open. Apply for the closed beta.
Written by Micky Irons, founder and chief executive of Mickai LTD.
Top comments (0)