PPN 017 Explained for AI Procurement
A practical explanation of PPN 017 and how to use its AI-transparency questions in procurement.
PPN 017: Improving transparency of AI use in procurement was published by the Cabinet Office on 17 February 2025. It provides optional questions intended to help identify the use of artificial intelligence in procurements and in the delivery of government services.
The notice was updated to reflect terminology introduced by the Procurement Act 2023 and the Procurement Regulations 2024.
What PPN 017 is trying to achieve
The practical problem is simple: AI may be present inside a service even when the procurement is not labelled as an “AI procurement.” It can appear in analytics, fraud detection, customer service, document processing, decision support, recruitment, search, summarisation or software development.
The buyer therefore needs enough transparency to understand where AI is being used and whether that use changes risk, assurance, contractual or operational requirements.
The procurement implication
Do not treat an affirmative answer to “Do you use AI?” as the end of the assessment. It should trigger a structured evidence request.
Useful follow-up areas include:
- what AI is used and for which function;
- whether the AI is supplier-developed or third-party;
- which model/provider dependencies are material;
- what customer data reaches the AI component;
- whether customer content is used for training or improvement;
- how outputs are tested and monitored;
- what human oversight applies;
- how material model or provider changes are communicated;
- how incidents are handled;
- what evidence supports supplier claims.
Suggested evidence crosswalk
Supplier says: “AI is used in the service”
Ask for: system description, intended purpose, material AI components and dependency map.
Supplier says: “Customer data is protected”
Ask for: data-flow evidence, locations, subprocessors, retention, access controls and contractual restrictions on training/use.
Supplier says: “The AI is accurate”
Ask for: evaluation methodology, relevant test results, limitations and evidence from representative use cases.
Supplier says: “There is human oversight”
Ask for: process design, approval points, escalation routes, user guidance and evidence that the oversight operates in practice.
Supplier says: “The service is secure”
Ask for: secure-development evidence, vulnerability management, testing, incident process, AI-specific threat considerations and material third-party dependencies.
How this connects to the wider government guidance
PPN 017 should be read alongside wider guidance rather than as a complete AI due-diligence framework. The AI Playbook for the UK Government covers safe, effective and secure AI use and how government organisations select, buy and deploy AI.
The DSIT AI Risk Management Toolkit, published 8 September 2026, is explicitly intended for people involved in designing, operating, procuring and delivering AI-enabled products.
The Sourcing Playbook, updated 15 June 2026, remains relevant to the wider commercial and sourcing process.
How AI TrustMark fits
AI TrustMark can turn transparency questions into an evidence structure: supplier identity, product architecture, data, security, governance, customer evidence and operational controls can be independently checked rather than left as unverified questionnaire responses.
AI TrustMark does not create government approval, procurement eligibility or a contract award. Buyers retain their own procurement decision.
See also: AI Supplier Due-Diligence Checklist and the AI Procurement Knowledge Base.