The Competition and Markets Authority (CMA) has released new guidance on procuring agentic AI for the public sector, and the full briefing can be found in the Elsewhen report on agentic ai for government. The CMA paper, dated 9 March 2026, flags consumer‑impact risks and sets out four key obligations for public‑sector buyers.
What the CMA says
According to ReedSmith, the CMA research paper warns that breaches involving AI agents can trigger fines of up to 10% of global annual turnover. The guidance also lists four practical duties: disclose when an AI agent is being used, avoid overstating capabilities, design systems to respect consumer‑rights legislation such as the Consumer Rights Act 2015, and monitor for anti‑competitive conduct that could amount to “agentic collusion”.
| Obligation | Description |
|---|---|
| Disclose AI agent use | Inform customers when they are interacting with an AI agent. |
| Do not overstate capabilities | Avoid claims that exceed the system’s proven performance. |
| Design for compliance | Build agents to respect consumer‑rights legislation (e.g., Consumer Rights Act 2015). |
| Monitor for anti‑competitive behaviour | Prevent ‘agentic collusion’ in pricing or market coordination. |
| Source: ReedSmith | |
Defining agentic AI
Elsewhen describes agentic AI as autonomous systems that can plan, decide and act without step‑by‑step human instruction. The firm argues that such agents can turn hours‑long manual processes into seconds, citing examples from planning records to hospital discharge workflows. The definition matters because it pushes buyers to look beyond surface‑level product sheets and assess how the underlying autonomy will interact with existing data‑flows and governance frameworks.
Data‑protection perspective from the ICO
The Information Commissioner’s Office (ICO) notes in its Tech‑Futures report that organisations remain responsible for data‑protection compliance even when AI agents make autonomous decisions. The report stresses the need to map controller‑processor relationships across the AI supply chain and to embed privacy‑by‑design safeguards from the outset.
Why buyers must compare methods and outcomes
For public‑sector procurement teams, the new CMA obligations translate into a checklist that goes far beyond the marketing language found in vendor brochures. Buyers should request evidence of real‑world performance, independent audits of algorithmic bias, and clear metrics on how the agent handles edge cases. Without such scrutiny, a supplier’s claim of “speed‑up to 100 times” – a figure that appears in Elsewhen’s narrative but is not independently verified – could mask hidden compliance costs.
Market context and next steps
Regulators across the EU are also sharpening their focus on autonomous systems, meaning UK buyers may soon face cross‑border compliance checks. The CMA’s guidance is the first concrete step, but the ICO’s data‑protection roadmap suggests that detailed impact assessments will become a prerequisite for any large‑scale rollout.
Public bodies should therefore embed the four CMA duties into their tender documents, allocate budget for third‑party audits, and set up internal monitoring teams that can flag “dark‑pattern” behaviours before they become enforcement matters.
For a recent example of large‑scale restructuring that required careful procurement planning, see the Lottomatica to merge with Cirsa, Blackstone to become 24% sh story. The VW board’s recent job‑cut announcement illustrates how public‑sector bodies must balance cost savings with compliance, as reported in VW board adds 50,000 jobs cuts, total 100,000, shares jump 1.
Further reading on the regulatory landscape can be found in the ICO tech‑futures report and the ReedSmith analysis. The UK government’s own publication on agentic AI and consumers provides additional context on expected productivity gains GOV.UK agentic AI and consumers.

