Edition 28.08.2026
Euro Gazette

Trade press for commerce and distribution · Europe

Procurement··2 min

Regulators Raise the Bar for Public‑Sector Procurement of Agentic AI

Public‑sector buyers must look beyond glossy brochures; new regulations demand proof that agentic AI meets compliance standards.

Katrin Ostermann

Public‑sector buyers must look beyond glossy brochures; the emerging regulatory framework demands clear evidence of how agentic state systems meet compliance standards.

Agentic AI refers to “AI systems composed of agents that can behave and interact autonomously in order to achieve their objectives,” a definition echoed by the UK government and detailed in the Elsewhen report.

Where early public discussion focused on personal assistants that schedule meetings or draft emails, the technology is now being piloted to automate complex public‑sector workflows – from processing planning records to handling asylum applications – promising to cut hours of manual work into seconds.

Regulatory Landscape Across the EU and UK

The UK Competition and Markets Authority (CMA) recently published a research paper highlighting that existing consumer‑protection and competition law will apply to autonomous AI agents, with potential fines of up to 10 % of global turnover for breaches. ReedSmith notes that both UK and EU regulators are mapping existing frameworks – consumer protection, competition, data protection and cybersecurity – onto agentic AI.

The Information Commissioner’s Office (ICO) has issued a “Tech Futures” report that outlines data‑protection responsibilities for organisations deploying such systems, warning that controllers remain liable for the data processed by autonomous agents. ICO Tech Futures report stresses the need for impact assessments and robust governance.

GOV.UK also publishes a guidance note that frames agentic AI as a new class of technology that will intersect with existing legislation, reinforcing the view that public‑sector contracts must embed compliance checks from the outset. GOV.UK guidance underscores the importance of transparency and accountability.

Implications for Public‑Sector Procurement

Procurement officers now have to translate these regulatory signals into concrete tender criteria. Rather than selecting a vendor based on brand name, they must evaluate:

  • How the solution demonstrates compliance with the Digital Services Act and national data‑protection rules.
  • Whether the provider can supply documented impact assessments and audit trails.
  • What governance mechanisms are built into the AI – for example, human‑in‑the‑loop controls or explainability features.

Recent court decisions on ICT procurement illustrate the growing demand for product‑neutral specifications. For instance, the Düsseldorfer Oberlandesgericht forced a municipality to rewrite an iPad tender to avoid vendor lock‑in, a precedent that can be extended to AI contracts.

Similarly, the Produkt‑Tags on YouTube story showed how technical specifications can become a battleground for fairness, reinforcing the need for clear, measurable criteria when evaluating agentic AI platforms.

Guidance for Buyers

To navigate this evolving landscape, buyers should adopt a structured evaluation framework:

Key Procurement Checks for Agentic AI
CheckWhat to Verify
Regulatory complianceAlignment with DSA, CMA guidance, ICO data‑protection obligations.
Methodology transparencyAvailability of model documentation, training data provenance, and audit logs.
Result validationIndependent testing results, performance metrics on public‑sector use cases.
Governance controlsHuman‑in‑the‑loop mechanisms, explainability, and incident response plans.
Source: ICO Tech Futures report; ReedSmith analysis; Elsewhen definition.

By demanding evidence for each of these checks, procurement teams can move the conversation from “which vendor sounds best” to “which solution demonstrably meets legal and operational requirements.”

As the regulatory environment solidifies, the market for agentic AI is likely to fragment into providers that can prove compliance and those that cannot. Early adopters who embed rigorous evaluation criteria will not only avoid costly penalties but also set a benchmark for responsible AI use across Europe.