Data

Beyond the pilot: Why the UK public sector needs an open source AI strategy

Written by Vic Gabrie | Sep 25, 2026, 10:03:39 AM

The UK stands at a pivotal moment in its technological history. As the government’s AI Opportunities Action Plan makes clear, artificial intelligence is no longer merely a tool for experimental pilots or back-office automation; it is a strategic imperative that will define the nation’s economic growth, job security, and the quality of public services for decades to come. With aspirations for the UK to become a global AI leader, we have to actively take control and steer our decisions rather than actively drift into whatever directions AI leaders are heading towards.

For CTOs, Directors, and Department Heads across Central Government, the challenge has shifted. The era of the “AI pilot” is ending, and the era of production-grade AI is beginning. To succeed, the UK public sector must transition from being an “AI taker”, reliant on opaque, externally managed proprietary models, to an “AI maker” that builds, hosts, and controls its own intelligent future.

The sovereignty gap and the “Mythos” warning

The risks of over-reliance on proprietary, closed models have recently come into sharp focus. The release of “Claude Mythos”, a frontier model capable of identifying and exploiting complex vulnerabilities, demonstrates the “ghost in the machine” potential of AI. When such powerful models are hosted exclusively outside the UK, and in some cases restricted or blocked from use outside the US due to export controls and geopolitical tensions, the UK faces a “sovereignty gap”.

If a department’s critical infrastructure relies on a black-box model that can be updated, restricted, or withdrawn by a foreign provider overnight, business continuity is at risk. The Government has an obligation to provide critical services to its citizens and this could potentially be compromised when relying on 3rd party AI providers.

One of the fundamental requirements for any government to function is trust from its citizens. The Organisation for Economic Co-operation and Development (OECD) establishes that public trust is built upon core institutional values, specifically integrity and openness (Brezzi et al., 2021) [1]. Without absolute integrity and openness regarding the Artificial Intelligence a government deploys, how can public institutions provide an honest, transparent, and corruption-free capability?

True sovereignty requires control over where and how AI runs, what data it uses, and the ability to switch models without being locked into a single ecosystem.

The danger of “Shadow AI”

When organisations started their journey to cloud, “Shadow IT” was prevalent across every organisation, credit cards were being used to build new services and capability in a fast and agile way. AI has the danger of a similar direction but with far greater consequences.

Without a clear enterprise-wide AI strategy and policy, departments face a burgeoning “Shadow AI” problem. Red Hat research indicates that 83% of UK organisations report unauthorized use of AI tools by employees. (Red Hat Survey) When civil servants use unapproved, public AI tools for government work, sensitive public data leaves the protected perimeter, creating significant privacy and security risks as highlighted by the NCSC in their blog, “The hidden risks of Shadow AI” [2].

Hosting models in-house, when appropriate, is the only way to provide the modern tools employees demand while maintaining strict data governance and transparency on how the models work. By offering an internal, secure alternative to public AI services, government departments can eliminate the need for Shadow AI and ensure every interaction is auditable, transparent, and compliant with UK regulations.

The strategic shift: from “taker” to “maker”

The AI Opportunities Action Plan outlines a bold vision for the UK to become a global AI leader. Central to this vision is the move toward becoming an “AI maker.”

For government departments, this means moving beyond consuming AI as a service from a handful of global providers. While SaaS-based AI offers a quick start, it creates long-term strategic dependencies and limits the ability to tailor AI to the specific needs of UK citizens and local cultural contexts.

This dependency is even more challenging when the models are withdrawn from use within a matter of hours, as we saw with Mythos, meaning that services reliant on them would need to be refactored.

Being an “AI maker” requires the ability to fine-tune models with private government data, host them in secure, jurisdictional environments, and ensure they remain operational even if global geopolitical conditions change. This transition is not just about technology, it is about retaining the UK's strategic autonomy.

Red Hat: agency, choice, and control

Red Hat’s approach to AI is built on three foundational pillars: Agency, Choice, and Control. These principles are designed to help the UK public sector bridge the gap between initial experimentation and sustainable, production-ready AI.

1. Choice: We believe in an open blueprint. Whether it is selecting the best open models, the most efficient hardware accelerators, or the right environment (on-premise, public cloud, or the edge), Red Hat provides the flexibility to run AI wherever and however it makes sense for your data and budget.

2. Control: Open source is the only approach that delivers the transparency required for public trust. With Red Hat AI, government organisations can inspect, modify, and audit the entire AI stack. We provide a security-hardened foundation that ensures you maintain operational authority over your models and your data.

3. Agency: Sovereignty is about acting on your own terms. An open hybrid AI platform enables organisations to rapidly customise, deploy and govern AI capabilities at scale across any environment, from hyperscaler to neocloud. This reduces dependence on a small group of proprietary vendors and empowers government teams to iterate and innovate at their own pace.

Conclusion: leading the future

The UK public sector has a unique opportunity to lead the global shift toward sovereign, open source AI. By aligning with the AI Opportunities Action Plan and focusing on “making” rather than just “taking,” Digital Directors and CTOs can build a resilient, transparent, and highly effective AI infrastructure.

AI is moving faster than any technology we have seen before. The right foundations, built on the pillars of choice, control, and agency, will ensure that as the technology evolves the UK can remain in control of its own digital destiny. It is time to go beyond the pilot and build the open future of UK public services.

Replicating success, not reinventing the wheel: AI in the public sector

How Red Hat OpenShift AI can help transform public services and infrastructure in the UK

Navigating the Mythos-haunted world of platform security

Red Hat Survey Explores the AI Sovereignty Gap and Disruption Risk Posed to UK Businesses

Red Hat Survey: UK Organizations Ready for Widespread AI Adoption, but Skills Gaps, High Costs and 'Shadow AI' Threaten Ambition

Unlocking the next layer of AI adoption in the UK

[1] Brezzi et al., 2021

[2] NCSC – The hidden risks of Shadow AI