Summary
The government has set out its intention to make the UK “a truly digital state”, transforming citizens’ experiences of the health, education, and justice systems, and other public services.
However, it has not set out what this means in detail or in practice and there is no clear plan to translate this vision into a reality. The “roadmap” for modern digital government would have been significantly improved by the inclusion of overarching metrics to assess delivery.
Our inquiry identified four building blocks for successful digital transformation, and four barriers to realising its benefits. The building blocks are:
- Money: Money is undoubtedly being spent on digital initiatives but inadequate data on digital spend prevents the government from making informed decisions or holding those responsible to account.
- People: The public sector needs more of the right people to deliver digital transformation of the state, and cultural change to ensure skills are valued and embedded in leadership levels.
- Information and data security: The current government is not holding itself to the standards of information security needed to secure public trust, or to prevent massive data breaches from happening again.
- Delivery: The government has a vision but needs a plan to deliver it. There is still time to turn things around but without a detailed, measurable plan, this digital transformation agenda may not succeed.
The barriers are:
- Hype: Optimistic projections and messaging, such as a supposed £45 billion annual productivity saving from digitisation, undermine the credibility of the government’s arguments, confuse and demoralise civil servants and encourage the belief that over-optimism, rather than achievement and honesty, will be rewarded.
- Legacy systems: Outdated and insecure systems are common across the public sector, making it harder to improve programming, maintain hardware and deliver interoperability. Failure to address this siloization will hamper delivery of the government’s vision and put citizens’ data increasingly at risk.
- Vendor lock-in: The public sector is dependent on a small number of large digital and technology providers, such as Palantir, Microsoft and AWS, and the government appears to be worryingly comfortable with this.
- Achieving sovereignty: Dependence on overseas providers of digital and technology is a weakness for adversaries to exploit. Developing truly sovereign alternatives would address this and support economic growth.
The government has added the rollout of a new digital ID by the end of the current Parliament to its to-do list. We support the decision for the new digital ID not to be mandatory, but there are uncertainties about its design, cost and scope. Even without these details, it is inarguable that without modernised digital infrastructure digital ID will struggle to succeed, and to keep citizens’ data secure.
Without public consent the government will struggle to deliver its digital transformation ambitions. This, and the other challenges identified in our report, are not insurmountable, but they have not yet been properly identified or addressed. If this does not change then the unrealised benefits to citizens from the digital transformation of public services will remain precisely that: unrealised.
1 Introduction
1. The government has set out its desire for the UK to become “a truly digital state – one where services work across institutional boundaries, and where digital credentials enable a more timesaving, personalised user experience”.1 Days after the 2024 general election it announced its intention to “unite efforts in the digital transformation of public services under one department”.2 The new government said it would create a new, expanded Government Digital Service (GDS), merging the existing GDS, the Central Digital and Data Office, and the Incubator for AI, and moving them from the Cabinet Office to the Department for Science, Innovation and Technology (DSIT).3 The then-Secretary of State said that the new digital centre (hereafter the new GDS) would provide “digital expertise and delivery… improving how the government and public services interact with citizens”.4
2. Previous ambitious digital transformation initiatives have delivered mixed results. The National Programme for IT in the NHS,5 the failed Care.data initiative,6 GOV.UK Verify,7 and the Horizon Post Office scandal offer examples of initiatives that either overspent, under-delivered or, in the case of the latter, led to a historic miscarriage of justice that affected thousands.8
The government’s vision
3. Despite these precedents, ministers have argued that in a world where our lives are increasingly digital, “people’s expectations are higher, and they keep rising” when it comes to accessing public services online,9 and that doing so should be made “as easy and secure as online banking”.10 The Cabinet Office has said that a planned digital ID would help the state move away from “old-fashioned and bureaucratic processes, towards proactive, hassle-free services that are delivered when people need them and in ways that work for them”.11 It is not clear whether the planned digital ID is a foundational building block of the government’s digital transformation agenda, or one initiative among many.
4. The UK public sector already “spends over £26 billion annually on digital technology, employs a workforce of nearly 100,000 digital and data professionals, and delivers millions of online transactions every day”.12 The government has identified the emergence of digital technologies such as generative AI as “a paradigm shift, bringing substantial new opportunities”.13 But, as our report will detail, it is less clear how the government plans to translate this vision into tangible outcomes.
Our inquiry
5. We launched our inquiry to examine what the priorities for the new GDS should be and how DSIT planned to implement the vision set out in its January 2025 blueprint for modern digital government.14 We held five evidence sessions, with representatives from central and local government, the NHS, technology providers, policy experts and civil society. We also drew on evidence from related workstreams, including on information and data security across government.15 We received written evidence from public sector bodies, businesses and trade associations, researchers, policy experts and the public. We are grateful to everyone who contributed to our inquiry.
6. Our inquiry highlighted four essential building blocks that should underpin the digital transformation of public services, which are set out in chapter 2. We also identified four barriers to achieving successful digital transformation, which are set out in chapter 3. In chapter 4 we consider the evolving plans to introduce a new digital ID and how this commitment relates to the government’s wider digital transformation agenda.16
2 Building blocks of digital transformation
7. Our inquiry examined a range of activities being undertaken by government departments and other public sector bodies. While some policy areas, such as healthcare or defence, have unique circumstances and considerations, we identified four ‘building blocks’ that are essential to the process of digital transformation across the public sector. This chapter describes these ‘building blocks’ and assesses how far the new digital centre of government is ensuring that they are in place.
Building block one: Money
8. The UK public sector spends over £26 billion per year on digital technology.17 Emily Middleton, a director-general at DSIT, told us that there is “serious fragmentation” in this spending across different departments and public bodies,18 and the government has said it hopes to introduce greater oversight, control and coherence.19 Below we explore its proposals for doing so and the challenges created by the current approach.
Spending on digital technology
9. Joe Hill, Director of Strategy at the Re:State think-tank, told us that public sector spending on digital technology:
is not particularly comprehensively mapped. Exercises to do that to the nth degree have been done over the years. They are always very stochastic… It takes them a very long time to do it, and they think, “Oh, God, we can’t keep doing that every year,” and they probably should.20
10. DSIT told us that “transparency is crucial to making accountability possible” in this area.21 Improvements are in the pipeline: GDS has said that from August 2026 “departments will start sharing annual outcome-based data on the performance of their services with each other, with secretaries of state held accountable in regular reviews”.22
Funding effective digital transformation
11. Data matters because it informs targeted policy interventions. As Laura Gilbert, former head of the Incubator for AI, put it, “if you leave the system the way it is, it is not going to fix itself. It requires massive investment”.23 The government has accepted that current funding models “do not reflect modern digital practice”, where technology spending has moved from “the acquisition and creation of hardware and software assets, to… continuous improvement and subscription services”.24 This will have implications for government spend reporting, an issue we reflect on below.
12. Only one in five respondents to a government survey of public sector leaders felt that the current approach “enabled effective investment in and running of digital services”.25 The review found that it was easier to secure capital, or investment, funding for digital spend than it was to secure resource, or day-to-day, funding, despite digital and data being an increasingly core aspect of delivery across the public sector.26 Less than half (43–46%) of new departmental digital and data spending comes from resource budgets, according to a 2021 estimate cited by government.27 DSIT told us that “most public sector digital funding is provided in a programme model more suitable for physical infrastructure projects”.28 The state of digital government review said that, as a consequence, public sector organisations are limited in their ability to “reliably secure funding for ‘as a service’ products, commit to modernisation and remediation” and that this drives “inefficient buying behaviours such as end of year purchasing decisions”.29 It also entrenches a decentralised approach to digital transformation.
Spend controls
13. Richard Pope, a former government official, told us that spend control, meaning the ability “to review upcoming digital projects and say yes or no to them”,30 allowed the original GDS to deliver significant savings. Laura Gilbert, the former head of the Incubator for AI, told us that “if we are not evaluating whether the spending is driving the outcome we want, we are wasting a lot of money”.31
14. In the blueprint for modern digital government, DSIT said that the new GDS would be able to apply “central spend assurance and digital spend controls”,32 with a new single, accessible service piloted from January 2025 and intended to be operational across all digital spend by December 2026.33 DSIT told us that it could “look directly at particular contracts that are coming forward and give that assurance process”, when a proposed contract had a value of £5 million or more.34
15. conclusion
Inadequate data on digital spend prevents the government from making informed decisions regarding policy interventions, and prevents those responsible from being properly held to account.
16. recommendation
GDS should require all departments and public bodies to disclose their annual spending on digital and data-driven activities, using guidance developed jointly with HM Treasury and with input from the National Audit Office. In its response to this report, the government should commit to publishing this annually, as part of Public Expenditure Statistical Analyses.
17. conclusion
Delivering successful digital transformation will require a new approach to digital and technology spend, underpinned by clear standards, approval processes, and lines of accountability. The current approach to funding, whereby it is easier to secure capital funding than resource, public sector organisations are limited in their ability to secure funds for ‘as a service’ products, and inefficient buying decisions are prevalent, does not reflect the reality of modern public service delivery, where spending on digital and technology should be viewed as a day-to-day undertaking. This creates inefficiencies, increases the likelihood that funds are wasted, and potentially undermines the bargaining power individual public bodies have over contractors and suppliers. Addressing this is made harder by the current, decentralised approach to digital transformation being taken across the public sector, where GDS provides advice and support but not always oversight.
18. recommendation
By the end of the current Spending Review period a meaningfully higher percentage of digital and technology spend should come from departmental resource budgets, as opposed to capital budgets, in order to better reflect the reality of modern public service delivery. We suggest a target of 75%, up from an estimated 43–46% in 2021. GDS and the Treasury should be given explicit responsibilities for driving pursuit of this target across government and for reporting annually on progress against it. We acknowledge that re-categorising such a significant amount of public spending would create operational and political difficulties, as a result of the different treatment of day-to-day and investment spending under the government’s fiscal rules; and that such changes would be highly challenging to deliver. Nevertheless, we believe that enabling better public service delivery is vital, and that such a change would help to do this.
19. recommendation
The new Government Digital Service (GDS) should develop and publish a comprehensive framework to evaluate the performance of digital spend, to include a set of metrics against which leaders of departments and public bodies can be held to account. The government should require each department and public body to publish annual progress reports against this framework.
Building block two: People
20. Just as public sector spending on digital technology and digital transformation is fragmented, so is the distribution of the approximately 100,000 people in public sector digital and data roles, leaving some bodies better placed than others to deliver effective digital transformation.35 Below we will examine the public sector workforce’s ability to deliver the government’s goals.
Digital transformation - views inside government
21. We heard different experiences from former government officials and researchers. Laura Gilbert, who worked across government as the first head of the Incubator for AI, told us that in her experience “right at the top, particularly on the political side, people are very excited to see what you could do”, and that “in the lower ranks of the civil service, there is a significant number of people who… want to see things change”.36
22. Jeni Tennison, Executive Director of Connected by Data and Chair of the GDS Responsible AI Advisory Panel, told us that there were parts of the public sector “that do good engagement work with the people who will need to adopt those technologies… talking through and involving them in things like shaping evaluations or shaping the actual technology”. She cited, as examples, the Department for Education’s public deliberation work on the use of AI in schools, and the Home Office’s approach to police use of AI tools.37
Digital and non-digital leadership
23. Laura Gilbert told us that she had encountered “people in probably quite senior digital data roles who I do not consider are technologist, data people. I wouldn’t hire them”.38 She argued that overall “there is a standard of digital expertise that is far below industry and far below where it ought to be”,39 and that often “… people in charge of technical delivery are existing civil servants who have been the director general of something else. There is a role free, so the system says, ‘This is available. You can go and do that’”.40 The state of digital government review found that “public sector digital leaders are not well represented at executive level and often report lower in their organisations, relative to policy, operational delivery, and finance colleagues”.41 Re:State told us that “one of the best services GDS can provide is trying to hire some of the best people from the private sector to come and do some of those tours of duty in government” in digital and technology roles.42
24. One consequence of the current distribution of digital capabilities across the public sector has been a reliance on third-party contractors. Of the £26 billion public sector digital and data spend in 2023, less than 20% was on permanent staff while 55% was on contractors.43 The review found that on average contractors in central government cost three times as much per year as civil servants, and that across the public sector, contractors account for approximately 18% of headcount but 40% of headcount cost”.44
25. During this inquiry we learned that the interim government chief digital officer would not be replaced upon departure but instead DSIT’s permanent secretary, in addition to their existing responsibilities, would lead on these areas.45 The Minister for Digital Government and Data told us that “keeping these issues at permanent secretary level is the way to get a cross-government approach to it”.46
Addressing workforce gaps
26. The roadmap for modern digital government outlined an ambition to turn government into “a leading digital career choice, equip leaders across the public sector with the expertise to champion digital transformation and strengthen inclusion and retention”.47 GDS says that it has developed “succession plans for all digital and data director and director general roles in central government”,48 although these have not yet been published.
27. The roadmap for modern digital government announced that from April 2026 assessment of all new directors and directors-general (although not permanent secretaries) “will include digital and data skills and behaviours, with digital expectations stated in job descriptions and reflected in performance objectives”.49 By December, central and local government bodies “will be expected to have a digital leader on their executive committee and a digital non-executive director on their board”.50
28. Owen Pengelly, a former government official, has noted that “technology investment of any kind is nothing without an equal focus on attracting, retaining, training, and where necessary redeploying, the right workforce skills”.51 Plans to upskill existing civil servants have been announced by the government,52 although it is not clear to what extent these and other reforms have been developed in consultation with trade unions representing civil servants. The then-Secretary of State told us in January 2025 that DSIT had “engaged trade unions on the strategic narrative for the set-up of the digital centre, the brand and how we engage our people in the change”;53 while the Cabinet Office said in March 2025 that it “regularly discusses Civil Service workforce matters with trade unions. These matters are wide ranging and include the use of new technology”.54 The FDA trade union and Fabian Society have argued that the government’s digital transformation ambitions “will falter without… a serious effort to work in partnership with staff and unions”.55 Their survey of civil servants has highlighted a feeling that:
change is being done to workers, not with them. Just 29% of those surveyed had been consulted on artificial intelligence tools in the workplace. Some also felt that engagement, where it occurred, was not sufficiently meaningful.56
29. The government has acknowledged that the public sector cannot compete on salaries with the private sector: “a typical central government cyber specialist earns 35% less than private sector peers, while civil service Chief Information Security Officers earn on average 40% less”.57 However, we heard that the public sector could offer a greater sense of mission. Laura Gilbert told us:
You have to be able to give people salaries in a range where they do not feel stupid for taking the job… When people are younger and they have a dream, they are prepared to take a lower salary, if you can get it to within the 30% level and people can see that they really can make a difference.58
She also proposed a ‘tour of duty’ idea to bring outside experts into government as part of their career development:
if we could communicate to the tech community and say, “Come in for two years, fix this and then you can go back to industry, and that’s a good thing to have done. It will feel good on your CV. It feels good for you personally. You get experience of something different,” there is a real sales pitch.59
30. GDS has promised “a competitive pay framework, high-impact work and clear pathways for new and existing talent”.60 A cross-government digital workforce strategy is in development,61 and the Prime Minister has said that one in 10 civil servants will work in technology and digital roles by 2030.62
31. conclusion
The public sector needs more of the right people to deliver the government’s ambitions for the digital transformation of the state. There are 100,000 digital and data professionals but not enough are in leadership roles, which are too often filled by generalists. Enthusiasm from non-experts at the top and insufficient skills at the coalface is a dangerous combination. Bringing more of the right skills into the public sector and ensuring that those in leadership roles have the necessary digital expertise will require reforms to recruitment and retention mechanisms, including pay, as well as a broader process of cultural transformation. Digital skills should not be treated as an optional extra, but as core to delivery in a modern state.
32. recommendation
GDS should publish the succession plans for all digital and data director and director general roles in central government, and develop and publish similar plans for the digital and data aspects of all permanent secretaries’ roles. The government should consider extending the requirement for all new directors and directors-general to be assessed against digital and data skills and behaviours to include future permanent secretaries. A Government Chief Digital Officer should be appointed at permanent secretary level.
33. recommendation
The cross-government digital workforce strategy should include detailed targets for departments and public bodies to meet by the end of the current Spending Review period, including: the publication of departmental plans to reduce the proportion of total workforce and cost of contractors in digital and technology roles; a clear plan to deliver on the Prime Minister’s commitment for one in 10 civil servants to be in technology and digital roles by 2030, as well as a definition of what constitutes a technology and digital role in the civil service; and a cultural transformation strategy to underpin digital transformation, developed in consultation with trade unions.
Building block three: Information and data security
34. While we were undertaking this inquiry, the Defence Secretary announced that a large-scale data breach that had taken place in 2022, when an official unintentionally leaked details of thousands of Afghan nationals who had worked with the UK.63 The shortfalls in security of information and data held by public bodies revealed by this leak, and others, has significant implications for the government’s digital transformation ambitions, and the rollout of the planned digital ID.
Information Security Review
35. We asked the Information Commissioner, DSIT and the Cabinet Office about the implications of the breach for public sector data hygiene.64 The Information Commissioner’s reply revealed the existence of an Information Security Review65 undertaken in 2023, and the current government then published it at our request.66 The Review analysed ten data breaches from across the public sector,67 and identified three common themes:
- A lack of sufficient controls over ad-hoc downloads / exports of aggregations of sensitive data from databases;
- The release of sensitive information via ‘wrong recipient’ emails, and the release of membership of sensitive groups through the placing of their addresses in visible fields; and
- The presence of hidden personal data within spreadsheets destined for publication or release.68
Further commitments
36. The Minister for Digital Government and Data told us that “13 and a half” of the Review’s 14 recommendations had been implemented, and said that while “it would be wrong to suggest… that all data will be 100% secure for ever because human error is very difficult to take out of the system”,69 his view was that “given that government share and use data billions of times a week, government data is, on the whole, very secure”.70 The recently-appointed Government Chief Data Officer (GCDO) told us that she would provide:
a single point of accountability for the coordination of data protection, compliance and risk. It will be my responsibility to make sure that government departments are aware of what they need to introduce in terms of the people, the process and the technologies that will, as far as we can, mitigate data protection loss.71
37. We heard that the GCDO would together with the Cabinet Office track public sector progress against a package of measures building on the Review’s recommendations.72 This includes a commitment to publish an annual assurance statement setting out “how people’s data is being kept safe and how new and proposed technologies and processes have been designed with trust and privacy in mind”.73 We asked the Minister for Digital Government and Data whether departments and public bodies that were not in compliance with GDS guidance on securing personal data would be prevented from adding their services to the planned digital ID, and while he declined to confirm that he told us that “the commitment in terms of digital ID is to have the most secure system and protections in place of anywhere across Government”.74 We will return to digital ID in chapter 4.
38. However, we also heard from the Cabinet Office that “a large number of departments are now using the Microsoft 365 Guidance for UK Government - Information Protection labelling solution”75 - that is, not all of them. The GCDO told us that 21 departments had accepted guidance to do so.76
Cultural change
39. The GCDO told us that she agreed with the Information Commissioner that “cultural change is needed across the public sector to give data protection greater prominence”.77 She said that “culture is about accountability and where we place accountability for data protection and where it is discussed”.78
40. When asked how the government would evidence cultural transformation, the Minister for Digital Government and Data pointed to “practice and technological change that puts those barriers in place that people then come up against, and that then changes the way in which they do things”,79 He said that the absence of government data leaks in future would be “assurance of how much progress we are making”.80
UK Biobank
41. In April 2026 the government announced that data held by the UK Biobank non-profit, which had been accessible to scientific researchers to support advances in healthcare and disease detection, had been advertised for sale on Alibaba e-commerce platforms in China.81 Characteristics in UK Biobank datasets include genetic and health information for 500,000 voluntary participants.82 The Minister for Digital Government and Data said that “it would be wrong for me to give 100% assurance—and UK Biobank cannot do so—that someone could not be identified” from the data made available.83
42. While access to Biobank data has been paused, three research institutions have been ejected from the study and the adverts in question removed, further listings have appeared and the government has acknowledged that more may follow.84 An internal review is underway. UK Biobank is independent of government but has received public funds via the Medical Research Council, UKRI’s Infrastructure Fund, and contributions of £16 million from the government in 2023 and £8 million in 2024.85
43. UK Biobank principal investigator and chief executive Professor Sir Rory Collins said that introducing manual checks on data download requests from researchers would cause:
very substantial delays not just in researchers being able to do the research but actually in being able to use those results to change the way patients are treated and their diseases are prevented… There will be a cost to the discoveries that are made by putting any kind of block like that in place.86
44. conclusion
It is a fundamental duty of government, public sector bodies and bodies in receipt of public funds to keep safe the data they hold on citizens. This duty has not been consistently upheld in the UK for some time. An Information Security Review, whose existence was - seemingly unnecessarily - kept secret until our intervention, examined a series of public sector data breaches, painting a picture of institutional failure and an incoherent approach to data hygiene.
45. conclusion
Successive governments have made a series of promises designed to address the institutional failings outlined in the Information Security Review. Yet we remain concerned that the current government is not holding itself to, or delivering, the standards of information and data security needed to secure and maintain public trust. This failure threatens the government’s digital transformation ambitions, and undermines public trust in its planned digital ID. Major cultural transformation is required to prevent mass data breaches from happening in the future.
46. conclusion
The advertisement of UK Biobank datasets on a Chinese e-commerce platform points to a particularly egregious example of inadequate data hygiene. The seriousness of the breach was compounded by a response that showed a lack of appreciation of the trust placed by 500,000 volunteers in the Biobank, a valuable study that depends on public confidence and trust in data management and data-sharing practices.
47. conclusion
UK Biobank is in receipt of public funds, and so the government should help it to ensure that failings are addressed as a matter of urgency. This incident underlines that contractual arrangements to protect citizens’ data must also be accompanied by robust technical protections.
48. recommendation
GDS and the Cabinet Office should publish quarterly reports on departmental and public sector body progress against the information and data security metrics it has committed to, together with its published principles for securing data in public services. These disclosures should be accessible via a single, publicly available tracker.
49. recommendation
In its response to this report, the government should set out how it intends to measure departmental and public body efforts to bring about difficult but necessary cultural changes in relation to data protection. It should name the departments and public bodies that have yet to adopt basic data hygiene practices, such as the use of Microsoft 365’s information protection labelling system, and state when this will be remedied.
50. recommendation
The findings of the internal review examining events at the UK Biobank should be published in full. In its response to this report the government and UKRI should set out the technical protections that will be put in place at the UK Biobank to ensure it properly protects citizens’ data. They should also set out their view on whether an organisation with such inadequate data hygiene is a suitable candidate to receive public funds.
Building block four: Delivery
51. The vision set out in the blueprint for modern digital government was described by the then-Secretary of State for Science, Innovation and Technology as “a long-term view that will take many years to bring about”.87 We will now examine how far the government has put forward a detailed delivery plan to accompany its vision.
Machinery of government
52. We heard mixed views about the relocation from the Cabinet Office to DSIT of the new GDS.88 Re:State think-tank observed that while the “breadth and complexity” of the Cabinet Office’s current responsibilities could prevent it from effectively coordinating digital transformation, “it may be that DSIT is also limited in its ability to drive reforms through other parts of government without the power of the ‘centre’ behind it”.89 Crown Hosting Data Centres said that the move represented “an improvement” but that more could be done, for example giving DSIT “greater control of departmental digital spend would give it greater influence”.90 Ultimately, Re:State told us, what mattered most was housing the entity responsible for delivery in “the strongest possible place to get the right outcome”.91
53. DSIT told us that the new GDS enjoyed “cross-government political backing” embodied by a new Digital Inter-Ministerial Group bringing together ministers from the Cabinet Office, DSIT and HM Treasury. It said that this group would ensure “high-level sponsorship across government, addressing a critical weakness of previous reform attempts”.92 It is not clear how many times this group has met since publication of the blueprint in January 2025, and while the roadmap published in January 2026 emphasised the “collective effort [underway] across government”, it did not mention the group.93
54. recommendation
In its response to this report the government should confirm how many times the Digital Inter-Ministerial Group has met since publication of the blueprint for modern digital government; and should publish the minutes, including attendance, from each of these meetings.
From blueprint to roadmap
55. While the blueprint for modern digital government identified six “kickstarter” initiatives to be prioritised by the new GDS,94 and a high-level six-point plan for government digital reform,95 Re:State warned that this could indicate that the government had been “tempted to boil the ocean… you try to do everything everywhere all at once, and none of it really happens”.96
56. Rachel Coldicutt, a technology researcher, told us that she saw in the blueprint “an idea that government wants people to be thinking about government a lot more than they are”.97 She said that the blueprint gave the impression of being “… something that has been produced in response to the question, ‘Can we have a vision?’ It doesn’t necessarily feel like a list of all the jobs that need to be done”.98 Similarly, Laura Gilbert, the former head of the Incubator for AI, told us that she would like to see “a lot more detail… a list of 15, 25 things we will achieve and we have an evaluation of what that will do, and that is the target for this Government”.99
57. The roadmap for modern digital government, which was published as a website rather than the usual command paper a year after the blueprint, offered a round-up of relevant activity departments and public bodies had undertaken since publication of the blueprint (or, in some cases, before) and a preview of forthcoming pieces of work. In total, it listed 113 activities that had been completed or were in progress, and 90 that were planned.100 An example of how DSIT’s priorities had changed since the publication of the blueprint came in April 2026 when the Minister for Digital Government and Data confirmed that internal pilots of in-house productivity tools had been paused after they had been “superseded by more modern, widely available platforms”, without specifying which ones.101
58. conclusion
The roadmap for modern digital government lacks overarching metrics by which the success or failure of delivery of the vision set out in the blueprint could be assessed. The decision to publish it as a website, rather than a command paper, also allows updates to be made without triggering GOV.UK alerts, which limits the extent to which the government can be held accountable for its delivery.
59. conclusion
The operational delays caused by the July 2024 machinery of government change, combined with shifting priorities, has hamstrung delivery of the vision set out in the blueprint. Unlike DSIT, the Cabinet Office is a coordinating department with the ability to drive change in the name of the Prime Minister. As digital is now essential to the operation of every government department and public body, we believe that the Cabinet Office should have housed the digital centre, not DSIT. However, at this stage in the Parliament, it would be unrealistic to recommend a reversal of the change. Instead, the government must follow the logic of the ‘digital centre of government’ label and empower GDS to deliver, with clear political and technical leadership.
60. recommendation
The government should commission an urgent review of the new GDS, to report no later than the September sitting of Parliament. The review should examine how GDS can set policies, coordinate effectively, and hold individual departments and public bodies to account for their delivery against specified digital transformation metrics and outcomes. These should be designed to ensure that digital transformation is done with the highest possible levels of public consent and trust.
61. recommendation
The Prime Minister should appoint a cabinet-level minister responsible for driving effective digital transformation across the public sector and supporting other ministers in this work. A permanent secretary-level Government Chief Digital Officer and head of GDS should be appointed to support them, with the publication of a detailed delivery plan in the form of a command paper as their first task. The government should publish a live dashboard of progress made against commitments set out in the delivery plan, which details what has been delivered, where priorities or delivery timetables have been revised, and any relevant policy announcements.
3 Barriers to effective digital transformation
62. Having detailed four building blocks that should underpin the digital transformation of public services, we will now turn to four barriers our inquiry identified to delivery of the government’s vision.
Barrier one: Hype
63. In communicating its vision and proposed outcomes for the new GDS and the transformation process the government has described both how the change will feel to citizens, and what it will deliver. Our first barrier to effective digital transformation is the impact of overly optimistic projections on the government’s ambitions.
The £45 billion
64. DSIT’s state of digital government review, published in January 2025, said:
over £45 billion per year of unrealised savings and productivity benefits, 4–7% of public sector spend, could be achieved through full potential digitisation of public sector services… [through] process simplification, AI-driven automation of manual tasks, greater availability, adoption of low-cost digital channels and reduced fraud through compliance automation.102
This figure has been widely cited by the Prime Minister and government ministers.103 Laura Gilbert, the former head of the Incubator for AI, told us that the figure was “… a reasonable guess, but of course it is a guess. It is very difficult to measure”.104 Richard Pope, another former GDS official, said that while “it is really hard to digitise an analogue or partially analogue service and not save money… projects that are predicated on saving money tend to create outcomes that do not work for the public particularly well”.105
Data
65. We asked DSIT for the data behind the estimate.106 It provided the following breakdown:
- Simplifying and automating delivery across the public sector (£36 billion);
- Migrating service processing to cheaper online channels (£4 billion); and
- Reducing fraud and error through digital compliance solutions (£6 billion).107
66. DSIT said that the £36 billion figure was arrived at by extrapolating across the entire public sector findings from a previous analysis that only covered central government, the NHS, and police personnel. The methodology also assumed that “100% of routine tasks and 10% of non-routine tasks can be automated”.108 It said that the estimate lacked “a specific timeframe for realisation, but [is] anticipated to be realised over the long term”.109
67. Nick Davies of the Institute for Government told us that, while there was “certainly inefficiency and duplicative spending across the public sector that you could spend more effectively” to improve productivity, cashable reductions in spending on such a scale would be difficult to achieve without “pretty meaningful headcount reductions, or reduc[ing] capital expenditure”.110 He argued that the most significant gains would come from “much simpler things like making sure the wi-fi worked or… a new laptop that did not take 30 minutes to turn on”.111
68. conclusion
The government is right to highlight the potential for technology to support better public service delivery. But its estimate that the digitisation of public services could deliver an annual saving of £45 billion is worryingly optimistic. While assumptions are an unavoidable part of economic projections, hyperbole diminishes the case for change.
69. recommendation
The new digital centre (GDS) should commission an independent economic analysis for each of the planned activities set out in the roadmap for modern digital government, giving a range of possible financial and economic outcomes for each commitment.
Barrier two: Legacy systems
70. Legacy systems, a terms which refers to IT infrastructure, systems, hardware, or processes that are an end-of-life product, no longer supported by suppliers, impossible to update, no longer cost-effective or whose use poses an unacceptable level of risk,112 were described by the National Audit Office (NAO) in 2013 as “a fact of life… the challenge is how intelligently they are managed, whether they are being retained, updated, replaced or phased out… performance in the public sector is patchy”.113 That assessment still applies today. Below we will assess the scale of the challenge legacy technology poses to the government’s digital transformation ambitions.
A longstanding challenge
71. In 2023 the Public Accounts Committee referred to efforts by government to assess 153 legacy systems across 16 departments.114 Continued use of these systems presents both inefficiency and data security challenges,115 while the National Cyber Security Centre has warned that “having a strategy to address technical legacy is a foundational precursor to engineering resilience”.116
72. In 2013 the government introduced a ‘Cloud First’ policy, which requires public sector bodies to “… default to Public Cloud first, using other solutions only where this is not possible.” This is mandatory for central government, and “strongly recommended” to the wider public sector.117 The state of digital government review found that “around 55% of central government organisations reported that over 60% of their estate is now on the cloud” but that the wider public sector falls short:118 “around 63% of the Home Office estate is on public cloud, while a large proportion of local government workloads and data remains on premise and NHS Cambridge has around 95% of its estate onpremises”.119
Data
73. We heard that a lack of authoritative data on legacy systems across the public sector was a significant issue. The state of digital government review found that “there is no comprehensive record of the scale of legacy IT across central government, let alone the entire public sector”.120 Estimates contained in the review were wide-ranging, for example that “an average of around 28% (ranging from 10–60%) of central government organisations’ technology estates are classified as legacy, with around 10-70% across police forces and around 10–50% across NHS trusts”.121 The review found that “around 15% of survey respondents could not even estimate the size of their legacy estate”,122 and in April 2026 the government confirmed that “a comprehensive account of which systems have been remediated or decommissioned is currently unavailable”.123
74. Jason Liggins, then-CEO of Crown Hosting Data Centres, a joint venture between the Cabinet Office and Ark Data Centres dedicated to supporting public sector bodies in migrating away from on-premises facilities,124 told us that “the terminology that government uses… is that all non-public-cloud IT assets are legacy, no matter whether they are old, new or contemporary”.125 The Minister for Digital Government and Data told us that he did not agree with that definition and that there are “… a huge list of different classifications that would make a system legacy”.126
Remediating legacy
75. Addressing legacy systems is made more difficult by a bias towards spending on “new programmes with insufficient prioritisation of the effective operation and maintenance of existing systems, especially legacy assets”, according to the state of digital government review.127 This is compounded by the fact that the maintenance of legacy systems is often “three to four times more expensive than that of modern alternatives”,128 and a tendency to reallocate funding initially intended for legacy remediation to other areas.129
76. However, there are potential solutions. Former government official Richard Pope highlighted the benefits of developing “common capabilities that cut across individual bits of legacy technology”,130 while GDS is working with HM Treasury “to ringfence key cyber security and legacy programmes”.131
77. We heard from DSIT that “over the next spending review period132 £20 billion is going into digital, data and technology service modernisation”.133 In the roadmap for modern digital government GDS promised to publish “stronger and more complete data on the use of legacy technology” across the public sector by June 2026,134 and a national cloud strategy by July 2026.135
78. conclusion
Legacy systems present huge efficiency, cost and security risks, and it is therefore deeply concerning that government still does not know the full scale of the problem. While it may be difficult for ministers to argue in favour of spending public funds on systems that still (just about) work, if legacy systems are not remediated, the government’s digital transformation ambitions will struggle to succeed.
79. recommendation
GDS should set up a Legacy Systems Taskforce with a remit to drive progress in remediating legacy systems across the public sector. It should be empowered to mandate action by departments and public sector bodies where necessary. The taskforce should publish the results of the promised legacy mapping exercise in as transparent a form as possible given security risks, together with a clear action plan to remove legacy systems from the UK public sector.
80. recommendation
We welcome GDS’s commitment to work with HM Treasury to ringfence funding to address legacy systems, particularly given the significant costs that remediation will create for departments and public bodies that are already under financial pressure. In its response to this report the government should confirm which programmes have been ringfenced or submitted for consideration.
81. recommendation
In its response to this report the government should set out how it intends to ensure that the public sector makes better use of the services provided by Crown Hosting.
Barrier three: Vendor lock-in
82. The government has said that digital public service delivery requires “the right mix of internal teams and external suppliers”.136 However, we heard that over-reliance on external suppliers can lead to vendor lock-in.137 This creates significant obstacles to switching between suppliers, such as the high costs of exiting long-term contracts, technical complexities, reliance on proprietary technologies and embedded idiosyncratic data formats.
83. This is a particularly acute challenge for the UK public sector, which is increasingly reliant on a small number of technology providers for the delivery of essential public services. Examples of high-profile powerful suppliers to the UK public sector where concerns or controversy have arisen are:
- Palantir Technologies, a software company, considered below;
- Fujitsu, which continues to hold government Strategic Supplier status,138 and has won approximately £500 million worth of new and extended contracts since a self-imposed moratorium on bidding for work with any new UK government customers, after the Post Office Horizon scandal.139 The government has said this is due to the need to ensure “continuity of essential public services”.140
- Microsoft, whose use of software licensing practices to reduce competition in cloud has been described as a “major concern” by the Competition and Markets Authority (CMA);141 and
- Amazon Web Services (AWS), which was the sole bidder for a ten-year, £472 million contract with HMRC to support data migration onto the cloud,142 has also been the subject of a CMA investigation,143 and when combined with Microsoft held an estimated 60–80% of the UK cloud infrastructure as a service market.144
Case study: Palantir
84. The relationship between the public sector and Palantir has attracted increasing public attention, in part because of its supply of software to the US military,145 and use by the federal Immigration and Customs Enforcement (ICE) agency.146 Comments about the NHS made by the company’s co-founder Peter Thiel, and a 22-point manifesto published by the company,147 have also raised concerns.148
85. Louis Mosley, head of Palantir’s business in the UK and Europe, distanced himself from Thiel’s comments and told us that the company existed “to support democratically-elected governments in delivering the mandate that they have been elected to deliver”.149 The company has published a 22-point manifesto based on the writing of CEO Alexander Karp, which argued that “the ability of free and democratic societies to prevail requires something more than moral appeal. It requires hard power, and hard power in this century will be built on software”.150 This is despite Louis Mosley telling us that the company “is not… political. We represent a diversity of political views and do not take political positions as a company”.151
Federated Data Platform
86. Palantir’s relationship with the NHS began during the covid-19 pandemic, when it was paid a nominal £1 fee to provide what Louis Mosley described to us as “aggregating data”.152 In November 2023 a consortium led by Palantir was awarded the contact to deliver the NHS Federated Data Platform (FDP), which “securely connects data, breaks down information silos, and provides insights to assist in decision-making, reduce costs, and improve patient outcomes”.153 The FDP contract is valued at £330 million over a maximum seven-year period, and will provide access for up to 240 NHS trusts and integrated care systems.154 The initial three-year commitment ends on 15 February 2027.155 A related £35 million contract was awarded to IQVIA, another US software company, in November 2023,156 after NHS England decided to split the overall FDP programme into separate contracts on data safeguarding grounds.157
Lock-in and data
87. Medconfidential, a campaign organisation, told us that over the duration of the initial three-year FDP contract Palantir will have “followed their commercial self-interests in attempting to burrow so deep into the NHS that they cannot be migrated away from and can name their fee”,158 although Louis Mosley told us that Palantir’s business model was:
to license the software. We do not derive any economic benefit from the data. The data belongs to the customer. We do not derive any economic benefit from the logic or code that they write to transform that data. Again, that is intellectual property that belongs to the customer.159
88. In May 2026 it was reported that Palantir had been given “‘unlimited access’ to identifiable patient data while working on a part of its flagship data platform”.160 This characterisation was disputed by Louis Mosley, who described it as “a specific technical permission inside one staging environment” held by “fewer than five Palantir employees who are UK-based, vetted and approved by NHS engineering leadership”.161 This is despite him saying in April that “in the same way that Microsoft Excel or Microsoft Word or email is used in the NHS… that is NHS data, Microsoft doesn’t have access to it, nor do we to NHS data”.162
89. A Chief Digital Information Officer at an NHS Trust told us that as NHS bodies were increasingly pressured “to do more with digital, we have potentially lost some of the good people who were subject to cuts” that have taken place simultaneously in areas such as digital.163 She agreed that this increased the risk of NHS bodies getting locked into bad contracts, “particularly if we want to do things at pace, because the way to get people in at pace is to use contracting and consultancy services. That would not be my preference”.164 Louis Mosley said:
if our services are very useful and they enable the government to deliver very important outcomes, arguably that creates a form of dependency… The best way, in my opinion, to manage that is commercially, to ensure that the contracts are done appropriately and that you have all the commercial controls you would expect in contracts of that kind. We, as a supplier, are very keen to engage with government to ensure that that happens.165
90. Some contributors to our inquiry argued that there is “nothing unique or special” about the company’s “off the shelf” offering,166 and the leadership of one NHS trust said that it would “lose functionality rather than gain it” if it were to adopt the FDP.167 However, Dr Vin Diwakar, then-National Director of Transformation (Interim) at NHS England, told us that 69% of NHS trusts had adopted the FDP and that “where they have implemented it, where there was a gap in their own systems, they have seen benefit”, in the form of additional operations, waiting list management and discharge co-ordination.168
91. We asked Dr Diwakar whether the planned Single Patient Record announced in the NHS 10-Year Plan would be based on open standards and open-source software, rather than proprietary systems provided by a single vendor.169 He told us that “we have not made any decision, so I cannot comment as to exactly what technology will be the best way of delivering it and how we will go about procuring it”.170 Legislation to implement the Single Patient Record was included in the 2026 King’s Speech,171 and the Cabinet Office has committed to introducing a public interest test under which government departments will be “required to assess whether a service can be delivered more effectively in-house, and if it cannot, a clear explanation must be published”.172
92. Since Palantir’s appearance before us in July 2025 it has continued to expand its presence in the UK public sector, most notably when the company was awarded a three-year, £240 million contract with the Ministry of Defence in December 2025 without a competitive tender.173
93. conclusion
Of the small number of technology providers that the UK public sector relies upon, Palantir concerns us most. In the United States it has supplied software for that country’s military and immigration services, supporting highly controversial policies and activities. Its co-founder has criticised the concept of a national health service and the company has issued a manifesto that makes explicitly political arguments, undermining what the head of their UK and European business told us. In the UK Palantir has increased its presence across the public sector despite this clear mismatch with UK values. We, however, are of the view that Palantir should not have such a significant role in the UK public sector, and that it is far from the only company capable of providing the data analysis ‘middleware’ required by public bodies.
94. conclusion
Our view that Palantir’s increasing presence across the public sector represents an unacceptable point of weakness is not ideologically motivated or driven by concerns about the quality of their products. The government should retain the ability to pick and choose individual suppliers and safeguard against the risk of vendor lock-in and debilitating dependencies, particularly in areas of critical national importance such as healthcare and national security infrastructure.
95. recommendation
The government should commit to exercising the February 2027 break clause in the Federated Data Platform contract and either develop an in-house replacement or seek an alternative developed by UK-owned and UK-based providers that are more compatible with UK values, and do not pursue either technical or contractual dependencies. It should publish a fully costed exit plan for the Federated Data Platform by the end of 2026.
96. recommendation
In its response to this report the government should confirm the exact nature of Palantir’s access to identifiable and non-identifiable patient data, on what statutory basis this was authorised, when, and by whom; and whether the Information Commissioner was consulted.
97. recommendation
The government should commit to wherever possible using UK-owned and UK-based suppliers to develop and implement the NHS Single Patient Record, and to awarding all associated contracts via open and transparent procurement processes.
98. recommendation
In its response to this report the government should set out the reasons for awarding a £240 million Ministry of Defence contract to Palantir without a competitive tender process.
Innovative alternatives
99. When questioned about Palantir and how more public contracts could go to UK start-ups and SMEs, Lord Vallance told us:
this is now more urgent than it has ever been … Now we have lots of start-ups; every day we do not get this right, we run the risk of them going elsewhere. This is really crucial.174
Similarly, Nick Davies of the Institute for Government told us that government was:
insufficiently strategic about how it uses its buying power… Often, it goes to market with highly specified solutions rather than clear outcomes that it wants to achieve… you often preclude potential innovations that you might have been able to procure.175
The government has promised to “increase flexibility and competition to deliver better value and more opportunities for SMEs to supply government”,176 departments have set targets for SME and start-up spend,177 and some, such as the Ministry of Defence, have set up units to provide “a single front door” for SMEs seeking to engage with them.178
100. Andrew Holway, founder of medical software startup Darwinist, said that vendor lock-in was “the primary barrier to NHS innovation”, and that the challenge was not:
organisational incompetence but rather being trapped in contracts with sole suppliers who hold them hostage, preventing the implementation of modern productivity tools that could save tens of billions of pounds.179
He said that startups such as his had experienced “immense headaches” because of incumbent suppliers’ “proprietary databases [and their status] as systems of record”.180 The Cabinet Office has acknowledged that “procurement rules work fine for companies that have a large procurement department to try to win the contracts, but they are not so good for start-ups or voluntary businesses”.181
101. recommendation
The best way for government to encourage innovation is by procuring it. The government should therefore require central departments and public bodies to spend a defined minimum percentage of their technology procurement budgets on products offered by UK-based and UK-owned start-ups and SMEs by the end of the current Spending Review period, and to publish quarterly updates on progress made against this.
Case study: Cloud
102. DSIT has said that government spends about £1 billion a year on cloud but that: “we know we are not getting the value for money that we should be… there is a lack of competition in some categories”.182 This issue was underlined in March 2026 when it emerged that Amazon Web Services (AWS) was the sole bidder for a ten-year, £472 million contract with HMRC to support data migration onto the cloud.183 This is despite reports of restrictive licensing practices,184 and high-profile instances of Microsoft and AWS outages in recent years, the latter of which the government said “affected a number of suppliers and departments”.185
103. The Open Cloud Coalition highlighted estimates that restrictive cloud licensing practices by Microsoft “could cost UK taxpayers over £300 million by the end of the current Parliament”,186 and suggested that “DSIT should consider a period of over-correction, including mandatory re-competition of high-risk or large-scale contracts, to break cycles of vendor lock-in and ensure fair market access”.187 In March 2026 the Competition and Markets Authority announced an investigation into, among other issues, “Microsoft’s use of software licensing reducing competition in cloud”.188
104. Public sector bodies are increasingly storing their data in the cloud, although the transition is happening at different rates.189 As is the case across the wider economy,190 a significant proportion of related contracts are held by AWS or Microsoft. Although DSIT has not confirmed the details and value of contracts held by each company,191 a “cloud consumption dashboard” is in development.192
105. The Minister for Digital Government and Data told us that he wanted to see the public sector “get the best bang for our buck in terms of economies of scale by buying it together”,193 while the roadmap for modern digital government promised that by December 2026 an “All of Government central cloud contract” would be agreed, creating “a standardised, marketplace-based framework that maximises government’s purchasing power”.194
106. conclusion
We believe that vendor lock-in should not be viewed as inevitable, and that dependence on a small number of suppliers does not automatically lead to better delivery of public services or better use of public money.
107. recommendation
GDS should produce a strategy to end vendor lock-in across the public sector, which includes targets for the diversification of suppliers across government departments and public bodies, progress against which is published on a quarterly basis.
108. conclusion
The public sector’s dependence on AWS and Microsoft’s cloud products undermines fair competition, fails to deliver value for money, can prevent domestic alternatives from scaling and—when outages occur—exposes a lack of resilience. The government is rightly seeking to coordinate cloud contracting, but this should be done in such a way as to ensure more, not less, competition.
109. recommendation
The promised cloud consumption dashboard should include not only a breakdown of contract awards by company but their value, details of any break clauses, specific licensing terms and a value for money assessment. The government should require public bodies to publish the value of individual cloud contracts within three months of their being awarded.
110. recommendation
The government should publish the findings of its investigation into the October 2025 AWS outage and its impact on suppliers and departments. In its response to this report, it should detail the steps it is taking to ensure greater resilience across public sector cloud infrastructure.
111. recommendation
In its response to this report the government should detail how the ‘All of Government’ cloud contract will prevent vendor lock-in. It should set out the engagement it has had with the Competition and Markets Authority on the development of the contract, and how the contract will embed a pro-competition approach to cloud procurement.
Barrier four: Achieving sovereignty
112. Sovereignty is increasingly emerging as a driver of tech policy debates, both in the UK and abroad.195 It relates closely to vendor lock-in and other procurement issues discussed above, and raises questions about what the government can and cannot control, with implications for its approach to digital transformation as well as to wider questions around the power of states versus global technology corporations.196 Below we consider the government’s position on this important debate, and its underlying strategy.
Defining sovereignty
113. The word ‘sovereignty’ does not appear in either the state of digital government review nor the blueprint for modern digital government, both published in January 2025.197 The Minister for Digital Government and Data told us that while there was currently “no single internationally recognised definition… DSIT is working to develop a comprehensive definition that can be used across the UK and for the UK Public Sector”.198
114. At the time of publication, this single definition is still in development,199 although we heard about several possibilities during our inquiry. The Secretary of State for DSIT told us that, in relation to AI:
… sovereign capability is about ensuring the UK has what it needs to become a global leader in AI. We need the domestic AI infrastructure to develop and deploy AI systems, and to support promising UK AI companies to scale and compete with incumbents.200
In April 2026 the Secretary of State argued that sovereignty is:
about reducing over-dependencies and increasing resilience in key national strategic priorities… So we secure greater control and greater leverage over the issues that matter most. And if you want true leverage for your country, you need to be a keystone in the global tech architecture–an indispensable partner.201
The Minister for AI and Online Safety has described technology sovereignty in similar terms, referring to:
a state’s ability to have strategic leverage when it comes to a technology, such that it can ensure ongoing access to critical inputs and ongoing assurance that its wider economic and national security objectives can be met more broadly. It is to take the best tools the world has to offer today, but also to shape the rest, and ultimately to make that which is critical here in Britain.202
Perhaps the clearest definition was offered by the chief executive of UK Research and Innovation:
There is infrastructure and hardware being UK domiciled rather than in the cloud or federated. There are models and tools to which we know that we have guaranteed access, either because they are generated internally or they are through an ally. There are skills and people. People who are available to work on things of application to national security need to have the right clearances. There is that layer to it. All three of those things play into sovereignty.203
115. The Prime Minister has said to the Liaison Committee that publishing a list of sovereign capabilities would “not [be] the right approach for either our national security or our economic growth”, and that any published list would risk “becoming outdated as technologies advance, and risks inadvertently telegraphing our specific vulnerabilities to hostile actors or signalling areas of strategic strength and drivers of growth to competitors”.204
116. conclusion
Sovereignty means different things to different people, including within government. Ultimately it comes down to choice, and having the ability to make choices rather than being dependent on individual providers is particularly important when it comes to technology. Leverage as the Secretary of State described it should be pursued, but can be constrained by the actions of unreliable and unpredictable players in an increasingly fragmented international system.
117. conclusion
Setting a cross-public sector definition of sovereignty and agreeing a strategy that is clear about the sectors and services where sovereign capability matters most, is a prerequisite for the effective use of technology by government departments and public bodies. We are therefore concerned by the current lack of clarity over how the government is approaching this important topic. Failure to agree and enact a clear sovereignty strategy is not only a barrier to the successful deployment of technology, but leaves the UK at the mercy of foreign commercial and state actors that do not share our strategic interests.
118. recommendation
In its response to this report the government should set out its definition of technology sovereignty and confirm whether a list of key capabilities or technologies where the government considers that the UK needs sovereign capability exists, whether this will be published or made available to Parliament, and if not, why not. The definition should be reviewed on an annual basis.
Sovereignty and digital transformation
119. Some of the underlying policy questions present in the sovereignty discussion are familiar. They are visible, for example, in the 2020 decision by the then-government to ban the purchase of 5G equipment manufactured by Chinese company Huawei, and to remove all Huawei equipment from 5G networks by the end of 2027.205
120. Since then the debate has sharpened thanks to both the changing nature of the United States’ relationship with allies under President Trump,206 and the UK government’s digital transformation ambitions. Concerns have been raised about the US Government’s Clarifying Lawful Overseas Use of Data (CLOUD) Act 2018, under which US-headquartered companies “could in principle be compelled to provide the US Government with access to UK customers’ data held in their UK data centres”.207
121. conclusion
The UK’s reliance on a small number of US-based providers for digital infrastructure and public service delivery is a strategic and economic vulnerability. The government’s digital transformation ambitions could be derailed at any time by a decision taken outside our shores based on the narrow interests of a foreign commercial or state actor.
Sovereign alternatives
122. The Prime Minister argued in March 2026 that “the more sovereign capability we have, the better”.208 The Secretary of State highlighted DSIT’s “advanced market commitment” of up to £100 million for “UK start-ups who are building high-quality AI hardware products but currently struggle to get off the ground without investment”; and the establishment of a Sovereign AI Unit, “backed by almost £500 million in investment to help build and scale AI capabilities on British shores”.209
123. Some public bodies overseas are already switching to domestic alternatives: the German state of Schleswig-Holstein has been gradually moving its systems from Microsoft to open-source alternatives, while France has developed the OVHcloud, a sovereign cloud service.210 One UK-specific suggestion is for the government to ringfence a percentage, increasing over time, of non-defence AI procurement spend across the public sector for UK-owned and UK-based firms.211 Professor Alan Brown of the University of Exeter has argued that, when it comes to technology procurement, the UK should “treat open source and open-weight models as first-class options… with evaluation criteria that credit them for the strategic flexibility they preserve”.212
124. However, developing wholly sovereign capabilities will be challenging. UK startups are often themselves reliant on US technology,213 and, despite moves by some European nations to develop alternatives to US providers, one report estimated that 80% of digital products and services in the EU are still provided by non-EU companies.214
125. recommendation
Building sovereign alternatives to US tech providers will require targeted support for start-ups in strategic sectors; a robust approach to competition policy that does not shy away from confrontation with incumbent firms but instead supports the development of a diverse ecosystem of providers; and establishing technology and digital procurement targets that build a more diverse and competitive landscape.
126. recommendation
The government should use its promised update to the Procurement Act 2023 to require public sector bodies to prioritise open-source tools and technology over proprietary offerings, to support innovative alternatives to incumbent suppliers and reduce the risk of vendor lock-in.
127. recommendation
The government should publish a technology sovereignty strategy that sets out how it intends to support the development of sovereign alternatives to incumbent providers across the public sector. Informed by the cross-government definition and list of required sovereign capabilities recommended above, the strategy should set stretching targets for the procurement of sovereign, open-source alternatives and detail further support for UK SMEs and start-ups that provide these services. The government should also launch advanced market commitments for the sectors deemed to require sovereign capabilities.
128. recommendation
The government should in its response to this report set out what contingencies it has in place to safeguard citizens’ data should the United States trigger data access provisions in the CLOUD Act 2018, and share any impact assessments that it has undertaken relating to this.
129. recommendation
As part of the government’s wider reset in its relations with the European Union, and its technology sovereignty strategy, DSIT should establish a unit dedicated to monitoring and disseminating digital government best practice from across the EU, with a remit to engage with Commission and member state-level bodies. This unit should have a particular focus on how the EU and its member states are encouraging the development of sovereign alternatives to incumbent providers.
4 Digital ID
130. As this report has shown, translating into reality the government’s vision for the digital transformation of public services, as set out in the blueprint for modern digital government, will be a major undertaking. Yet while this inquiry was underway the government made a further, equally significant announcement: the introduction of a new digital ID.215 In this chapter we will examine what has been proposed, and how it relates to the government’s wider ambitions.
Scope
131. In September 2025 the government said that the new digital ID “would be mandatory for Right to Work checks by the end of the Parliament”,216 although in January 2026 it reversed this.217 The government initially framed the initiative as helping to “combat illegal working while making it easier for the vast majority of people to use vital government services”,218 while the consultation launched in March 2026 was billed as being on “making public services quicker, easier and more secure to access with digital ID”.219 The Chief Secretary to the Prime Minister has said that public services need to “catch up” with services like online banking, and that digital ID will help achieve this.220
132. The scope of the new digital ID is, at the time of publication, still to be determined, although the government has said that “the range of ways people can choose to use their digital ID will grow over time”, and that while it “will provide a simple access point for new, modern digital public services”, having one will not be a requirement for accessing these services.221 Gaia Marcus of the Ada Lovelace Institute told us that “the public are very nervous about anything that is felt as driving a two-tier society and any sort of scope creep”.222
133. Speaking to us before the mandatory element of the digital ID was dropped, Jeni Tennison, of Connected by Data, said that creating “a centralised record of what checks are done by whom in what places is of particular risk to privacy, because that can reveal a lot about our lives”.223 She said that “the question about what gets recorded behind the scenes, about the checks themselves, who has access to that data and the governance around it” should be subject to close scrutiny.224
134. conclusion
While technology can help improve people’s experience of public services, and activities such as banking are increasingly done online, the difference between interactions with the state and a bank is that citizens have a choice about which bank to interact with and can freely move between different providers. We therefore welcome confirmation that the new digital ID will not be mandatory.
Design
135. At the time of writing the design of the new digital ID is still to be confirmed, although the government has said that it “will build on existing systems that are already operating as trusted parts of government”, specifically GOV.UK One Login, the GOV.UK Wallet, the passport service and the eVisa service.225 The Chief Secretary to the Prime Minister has said that he would like government to:
build the technology ourselves, in-house, as opposed to outsourcing it to, say, a big American tech company, and integrate it into what we already have, so that it does not become a huge, stand-alone, multibillion-pound, 10-year and huge Bill-driven piece of Government IT, but… can be done quite simply.226
136. Reforms to the passport application process have been highlighted as a successful example of digital transformation,227 but we have heard concerns about One Login and the eVisa system. One Login was temporarily removed from the list of the government’s approved providers, after a supplier allowed its certification against the government’s own Digital Identity and Attributes Trust Framework to lapse.228
137. In evidence to the Home Affairs Committee the3Million, a campaign group, said that the eVisa system, which has been rolled out to 10 million people despite still being labelled as beta eight years after launching in 2018,229 produces “an unacceptably high number of errors”,230 such as incorrect images or statuses.231 The committee heard that the system is based on over 90 separate systems, many of which are legacy.232
Cost
138. In November 2025, the Office for Budget Responsibility (OBR) estimated that the new digital ID would cost £1.8 billion over the next three years, and said that, though the government had said it planned to meet the cost from existing departmental settlements, “no specific savings have yet been identified” to cover this.233
139. The Chief Secretary to the Prime Minister has said that he is “… not clear how [the OBR] came to that view… we do not have a number yet”,234 while the Minister for Digital Government and Data told us that the eventual cost could “only really be measured after the consultation has closed and been analysed, and we determine which kind of system we will build”.235 When asked whether DSIT, which has responsibility for “the technical design and build of the system”,236 would be required to cover the cost, he said that “money from other Departments will have to come in for the use cases”.237
140. conclusion
It would be irresponsible to roll out a digital ID built on the UK’s current digital infrastructure. The public sector holds citizens’ data on trust, and should therefore hold itself to a higher standard. The operational and security problems relating to the eVisa system, One Login’s temporary loss of certification against the government’s own digital identity framework, and the inadequate data hygiene examined in this report all make this clear.
141. conclusion
The digital ID will be a significant test of the government’s wider digital transformation ambitions: if it does not succeed, or results in a worse experience for citizens when they interact with government, there will be far-reaching political consequences. Citizens’ consent is a pre-requisite for delivering digital transformation, and the widespread concern about the presence of Palantir in the public sector is an example of the risks associated with a lack of trust in suppliers.
142. conclusion
Uncertainty over the eventual cost of the digital ID scheme make it impossible to take an informed view on whether it will prove a worthwhile undertaking, even if the operational and security challenges examined in this report were to be resolved. The government was, however, right to say that the digital ID should be built in-house, from the perspective of both cost and public trust.
143. recommendation
The announcement of the government’s final decision on digital ID should be accompanied by full costings and a full impact assessment, as well as details of controls to ensure the scheme, if it is taken forward, does not exceed its delivery timetable or agreed budget.
144. recommendation
If external suppliers are deemed necessary to support the development or implementation of the new digital ID, no contracts relating to the development or implementation of the new digital ID should be awarded without a competitive tender process, and all contracts should be published in full. The government should announce the decision to use external suppliers to Parliament before tendering.
145. recommendation
If the government decides to proceed with the new digital ID, Parliament should be given an opportunity to vote on each use case before it is added and given full access to the government’s internal impact and cost assessments to inform its decision.
Conclusions and recommendations
Building blocks of digital transformation
Building block one: Money
1. Inadequate data on digital spend prevents the government from making informed decisions regarding policy interventions, and prevents those responsible from being properly held to account. (Conclusion, Paragraph 15)
2. GDS should require all departments and public bodies to disclose their annual spending on digital and data-driven activities, using guidance developed jointly with HM Treasury and with input from the National Audit Office. In its response to this report, the government should commit to publishing this annually, as part of Public Expenditure Statistical Analyses. (Recommendation, Paragraph 16)
3. Delivering successful digital transformation will require a new approach to digital and technology spend, underpinned by clear standards, approval processes, and lines of accountability. The current approach to funding, whereby it is easier to secure capital funding than resource, public sector organisations are limited in their ability to secure funds for ‘as a service’ products, and inefficient buying decisions are prevalent, does not reflect the reality of modern public service delivery, where spending on digital and technology should be viewed as a day-to-day undertaking. This creates inefficiencies, increases the likelihood that funds are wasted, and potentially undermines the bargaining power individual public bodies have over contractors and suppliers. Addressing this is made harder by the current, decentralised approach to digital transformation being taken across the public sector, where GDS provides advice and support but not always oversight. (Conclusion, Paragraph 17)
4. By the end of the current Spending Review period a meaningfully higher percentage of digital and technology spend should come from departmental resource budgets, as opposed to capital budgets, in order to better reflect the reality of modern public service delivery. We suggest a target of 75%, up from an estimated 43–46% in 2021. GDS and the Treasury should be given explicit responsibilities for driving pursuit of this target across government and for reporting annually on progress against it. We acknowledge that re-categorising such a significant amount of public spending would create operational and political difficulties, as a result of the different treatment of day-to-day and investment spending under the government’s fiscal rules; and that such changes would be highly challenging to deliver. Nevertheless, we believe that enabling better public service delivery is vital, and that such a change would help to do this. (Recommendation, Paragraph 18)
5. The new Government Digital Service (GDS) should develop and publish a comprehensive framework to evaluate the performance of digital spend, to include a set of metrics against which leaders of departments and public bodies can be held to account. The government should require each department and public body to publish annual progress reports against this framework. (Recommendation, Paragraph 19)
Building block two: People
6. The public sector needs more of the right people to deliver the government’s ambitions for the digital transformation of the state. There are 100,000 digital and data professionals but not enough are in leadership roles, which are too often filled by generalists. Enthusiasm from non-experts at the top and insufficient skills at the coalface is a dangerous combination. Bringing more of the right skills into the public sector and ensuring that those in leadership roles have the necessary digital expertise will require reforms to recruitment and retention mechanisms, including pay, as well as a broader process of cultural transformation. Digital skills should not be treated as an optional extra, but as core to delivery in a modern state. (Conclusion, Paragraph 31)
7. GDS should publish the succession plans for all digital and data director and director general roles in central government, and develop and publish similar plans for the digital and data aspects of all permanent secretaries’ roles. The government should consider extending the requirement for all new directors and directors-general to be assessed against digital and data skills and behaviours to include future permanent secretaries. A Government Chief Digital Officer should be appointed at permanent secretary level. (Recommendation, Paragraph 32)
8. The cross-government digital workforce strategy should include detailed targets for departments and public bodies to meet by the end of the current Spending Review period, including: the publication of departmental plans to reduce the proportion of total workforce and cost of contractors in digital and technology roles; a clear plan to deliver on the Prime Minister’s commitment for one in 10 civil servants to be in technology and digital roles by 2030, as well as a definition of what constitutes a technology and digital role in the civil service; and a cultural transformation strategy to underpin digital transformation, developed in consultation with trade unions. (Recommendation, Paragraph 33)
Building block three: Information and data security
9. It is a fundamental duty of government, public sector bodies and bodies in receipt of public funds to keep safe the data they hold on citizens. This duty has not been consistently upheld in the UK for some time. An Information Security Review, whose existence was - seemingly unnecessarily - kept secret until our intervention, examined a series of public sector data breaches, painting a picture of institutional failure and an incoherent approach to data hygiene. (Conclusion, Paragraph 44)
10. Successive governments have made a series of promises designed to address the institutional failings outlined in the Information Security Review. Yet we remain concerned that the current government is not holding itself to, or delivering, the standards of information and data security needed to secure and maintain public trust. This failure threatens the government’s digital transformation ambitions, and undermines public trust in its planned digital ID. Major cultural transformation is required to prevent mass data breaches from happening in the future. (Conclusion, Paragraph 45)
11. The advertisement of UK Biobank datasets on a Chinese e-commerce platform points to a particularly egregious example of inadequate data hygiene. The seriousness of the breach was compounded by a response that showed a lack of appreciation of the trust placed by 500,000 volunteers in the Biobank, a valuable study that depends on public confidence and trust in data management and data-sharing practices. (Conclusion, Paragraph 46)
12. UK Biobank is in receipt of public funds, and so the government should help it to ensure that failings are addressed as a matter of urgency. This incident underlines that contractual arrangements to protect citizens’ data must also be accompanied by robust technical protections. (Conclusion, Paragraph 47)
13. GDS and the Cabinet Office should publish quarterly reports on departmental and public sector body progress against the information and data security metrics it has committed to, together with its published principles for securing data in public services. These disclosures should be accessible via a single, publicly available tracker. (Recommendation, Paragraph 48)
14. In its response to this report, the government should set out how it intends to measure departmental and public body efforts to bring about difficult but necessary cultural changes in relation to data protection. It should name the departments and public bodies that have yet to adopt basic data hygiene practices, such as the use of Microsoft 365’s information protection labelling system, and state when this will be remedied. (Recommendation, Paragraph 49)
15. The findings of the internal review examining events at the UK Biobank should be published in full. In its response to this report the government and UKRI should set out the technical protections that will be put in place at the UK Biobank to ensure it properly protects citizens’ data. They should also set out their view on whether an organisation with such inadequate data hygiene is a suitable candidate to receive public funds. (Recommendation, Paragraph 50)
Building block four: Delivery
16. In its response to this report the government should confirm how many times the Digital Inter-Ministerial Group has met since publication of the blueprint for modern digital government; and should publish the minutes, including attendance, from each of these meetings. (Recommendation, Paragraph 54)
17. The roadmap for modern digital government lacks overarching metrics by which the success or failure of delivery of the vision set out in the blueprint could be assessed. The decision to publish it as a website, rather than a command paper, also allows updates to be made without triggering GOV.UK alerts, which limits the extent to which the government can be held accountable for its delivery. (Conclusion, Paragraph 58)
18. The operational delays caused by the July 2024 machinery of government change, combined with shifting priorities, has hamstrung delivery of the vision set out in the blueprint. Unlike DSIT, the Cabinet Office is a coordinating department with the ability to drive change in the name of the Prime Minister. As digital is now essential to the operation of every government department and public body, we believe that the Cabinet Office should have housed the digital centre, not DSIT. However, at this stage in the Parliament, it would be unrealistic to recommend a reversal of the change. Instead, the government must follow the logic of the ‘digital centre of government’ label and empower GDS to deliver, with clear political and technical leadership. (Conclusion, Paragraph 59)
19. The government should commission an urgent review of the new GDS, to report no later than the September sitting of Parliament. The review should examine how GDS can set policies, coordinate effectively, and hold individual departments and public bodies to account for their delivery against specified digital transformation metrics and outcomes. These should be designed to ensure that digital transformation is done with the highest possible levels of public consent and trust. (Recommendation, Paragraph 60)
20. The Prime Minister should appoint a cabinet-level minister responsible for driving effective digital transformation across the public sector and supporting other ministers in this work. A permanent secretary-level Government Chief Digital Officer and head of GDS should be appointed to support them, with the publication of a detailed delivery plan in the form of a command paper as their first task. The government should publish a live dashboard of progress made against commitments set out in the delivery plan, which details what has been delivered, where priorities or delivery timetables have been revised, and any relevant policy announcements. (Recommendation, Paragraph 61)
Barriers to effective digital transformation
Barrier one: Hype
21. The government is right to highlight the potential for technology to support better public service delivery. But its estimate that the digitisation of public services could deliver an annual saving of £45 billion is worryingly optimistic. While assumptions are an unavoidable part of economic projections, hyperbole diminishes the case for change. (Conclusion, Paragraph 68)
22. The new digital centre (GDS) should commission an independent economic analysis for each of the planned activities set out in the roadmap for modern digital government, giving a range of possible financial and economic outcomes for each commitment. (Recommendation, Paragraph 69)
Barrier two: Legacy systems
23. Legacy systems present huge efficiency, cost and security risks, and it is therefore deeply concerning that government still does not know the full scale of the problem. While it may be difficult for ministers to argue in favour of spending public funds on systems that still (just about) work, if legacy systems are not remediated, the government’s digital transformation ambitions will struggle to succeed. (Conclusion, Paragraph 78)
24. GDS should set up a Legacy Systems Taskforce with a remit to drive progress in remediating legacy systems across the public sector. It should be empowered to mandate action by departments and public sector bodies where necessary. The taskforce should publish the results of the promised legacy mapping exercise in as transparent a form as possible given security risks, together with a clear action plan to remove legacy systems from the UK public sector. (Recommendation, Paragraph 79)
25. We welcome GDS’s commitment to work with HM Treasury to ringfence funding to address legacy systems, particularly given the significant costs that remediation will create for departments and public bodies that are already under financial pressure. In its response to this report the government should confirm which programmes have been ringfenced or submitted for consideration. (Recommendation, Paragraph 80)
26. In its response to this report the government should set out how it intends to ensure that the public sector makes better use of the services provided by Crown Hosting. (Recommendation, Paragraph 81)
Barrier three: Vendor lock-in
27. Of the small number of technology providers that the UK public sector relies upon, Palantir concerns us most. In the United States it has supplied software for that country’s military and immigration services, supporting highly controversial policies and activities. Its co-founder has criticised the concept of a national health service and the company has issued a manifesto that makes explicitly political arguments, undermining what the head of their UK and European business told us. In the UK Palantir has increased its presence across the public sector despite this clear mismatch with UK values. We, however, are of the view that Palantir should not have such a significant role in the UK public sector, and that it is far from the only company capable of providing the data analysis ‘middleware’ required by public bodies. (Conclusion, Paragraph 93)
28. Our view that Palantir’s increasing presence across the public sector represents an unacceptable point of weakness is not ideologically motivated or driven by concerns about the quality of their products. The government should retain the ability to pick and choose individual suppliers and safeguard against the risk of vendor lock-in and debilitating dependencies, particularly in areas of critical national importance such as healthcare and national security infrastructure. (Conclusion, Paragraph 94)
29. The government should commit to exercising the February 2027 break clause in the Federated Data Platform contract and either develop an in-house replacement or seek an alternative developed by UK-owned and UK-based providers that are more compatible with UK values, and do not pursue either technical or contractual dependencies. It should publish a fully costed exit plan for the Federated Data Platform by the end of 2026. (Recommendation, Paragraph 95)
30. In its response to this report the government should confirm the exact nature of Palantir’s access to identifiable and non-identifiable patient data, on what statutory basis this was authorised, when, and by whom; and whether the Information Commissioner was consulted. (Recommendation, Paragraph 96)
31. The government should commit to wherever possible using UK-owned and UK-based suppliers to develop and implement the NHS Single Patient Record, and to awarding all associated contracts via open and transparent procurement processes. (Recommendation, Paragraph 97)
32. In its response to this report the government should set out the reasons for awarding a £240 million Ministry of Defence contract to Palantir without a competitive tender process. (Recommendation, Paragraph 98)
33. The best way for government to encourage innovation is by procuring it. The government should therefore require central departments and public bodies to spend a defined minimum percentage of their technology procurement budgets on products offered by UK-based and UK-owned start-ups and SMEs by the end of the current Spending Review period, and to publish quarterly updates on progress made against this. (Recommendation, Paragraph 101)
34. We believe that vendor lock-in should not be viewed as inevitable, and that dependence on a small number of suppliers does not automatically lead to better delivery of public services or better use of public money. (Conclusion, Paragraph 106)
35. GDS should produce a strategy to end vendor lock-in across the public sector, which includes targets for the diversification of suppliers across government departments and public bodies, progress against which is published on a quarterly basis. (Recommendation, Paragraph 107)
36. The public sector’s dependence on AWS and Microsoft’s cloud products undermines fair competition, fails to deliver value for money, can prevent domestic alternatives from scaling and—when outages occur—exposes a lack of resilience. The government is rightly seeking to coordinate cloud contracting, but this should be done in such a way as to ensure more, not less, competition. (Conclusion, Paragraph 108)
37. The promised cloud consumption dashboard should include not only a breakdown of contract awards by company but their value, details of any break clauses, specific licensing terms and a value for money assessment. The government should require public bodies to publish the value of individual cloud contracts within three months of their being awarded. (Recommendation, Paragraph 109)
38. The government should publish the findings of its investigation into the October 2025 AWS outage and its impact on suppliers and departments. In its response to this report, it should detail the steps it is taking to ensure greater resilience across public sector cloud infrastructure. (Recommendation, Paragraph 110)
39. In its response to this report the government should detail how the ‘All of Government’ cloud contract will prevent vendor lock-in. It should set out the engagement it has had with the Competition and Markets Authority on the development of the contract, and how the contract will embed a pro-competition approach to cloud procurement. (Recommendation, Paragraph 111)
Barrier four: Achieving sovereignty
40. Sovereignty means different things to different people, including within government. Ultimately it comes down to choice, and having the ability to make choices rather than being dependent on individual providers is particularly important when it comes to technology. Leverage as the Secretary of State described it should be pursued, but can be constrained by the actions of unreliable and unpredictable players in an increasingly fragmented international system. (Conclusion, Paragraph 116)
41. Setting a cross-public sector definition of sovereignty and agreeing a strategy that is clear about the sectors and services where sovereign capability matters most, is a prerequisite for the effective use of technology by government departments and public bodies. We are therefore concerned by the current lack of clarity over how the government is approaching this important topic. Failure to agree and enact a clear sovereignty strategy is not only a barrier to the successful deployment of technology, but leaves the UK at the mercy of foreign commercial and state actors that do not share our strategic interests. (Conclusion, Paragraph 117)
42. In its response to this report the government should set out its definition of technology sovereignty and confirm whether a list of key capabilities or technologies where the government considers that the UK needs sovereign capability exists, whether this will be published or made available to Parliament, and if not, why not. The definition should be reviewed on an annual basis. (Recommendation, Paragraph 118)
43. The UK’s reliance on a small number of US-based providers for digital infrastructure and public service delivery is a strategic and economic vulnerability. The government’s digital transformation ambitions could be derailed at any time by a decision taken outside our shores based on the narrow interests of a foreign commercial or state actor. (Conclusion, Paragraph 121)
44. Building sovereign alternatives to US tech providers will require targeted support for start-ups in strategic sectors; a robust approach to competition policy that does not shy away from confrontation with incumbent firms but instead supports the development of a diverse ecosystem of providers; and establishing technology and digital procurement targets that build a more diverse and competitive landscape. (Recommendation, Paragraph 125)
45. The government should use its promised update to the Procurement Act 2023 to require public sector bodies to prioritise open-source tools and technology over proprietary offerings, to support innovative alternatives to incumbent suppliers and reduce the risk of vendor lock-in. (Recommendation, Paragraph 126)
46. The government should publish a technology sovereignty strategy that sets out how it intends to support the development of sovereign alternatives to incumbent providers across the public sector. Informed by the cross-government definition and list of required sovereign capabilities recommended above, the strategy should set stretching targets for the procurement of sovereign, open-source alternatives and detail further support for UK SMEs and start-ups that provide these services. The government should also launch advanced market commitments for the sectors deemed to require sovereign capabilities. (Recommendation, Paragraph 127)
47. The government should in its response to this report set out what contingencies it has in place to safeguard citizens’ data should the United States trigger data access provisions in the CLOUD Act 2018, and share any impact assessments that it has undertaken relating to this. (Recommendation, Paragraph 128)
48. As part of the government’s wider reset in its relations with the European Union, and its technology sovereignty strategy, DSIT should establish a unit dedicated to monitoring and disseminating digital government best practice from across the EU, with a remit to engage with Commission and member state-level bodies. This unit should have a particular focus on how the EU and its member states are encouraging the development of sovereign alternatives to incumbent providers. (Recommendation, Paragraph 129)
Digital ID
49. While technology can help improve people’s experience of public services, and activities such as banking are increasingly done online, the difference between interactions with the state and a bank is that citizens have a choice about which bank to interact with and can freely move between different providers. We therefore welcome confirmation that the new digital ID will not be mandatory. (Conclusion, Paragraph 134)
50. It would be irresponsible to roll out a digital ID built on the UK’s current digital infrastructure. The public sector holds citizens’ data on trust, and should therefore hold itself to a higher standard. The operational and security problems relating to the eVisa system, One Login’s temporary loss of certification against the government’s own digital identity framework, and the inadequate data hygiene examined in this report all make this clear. (Conclusion, Paragraph 140)
51. The digital ID will be a significant test of the government’s wider digital transformation ambitions: if it does not succeed, or results in a worse experience for citizens when they interact with government, there will be far-reaching political consequences. Citizens’ consent is a pre-requisite for delivering digital transformation, and the widespread concern about the presence of Palantir in the public sector is an example of the risks associated with a lack of trust in suppliers. (Conclusion, Paragraph 141)
52. Uncertainty over the eventual cost of the digital ID scheme make it impossible to take an informed view on whether it will prove a worthwhile undertaking, even if the operational and security challenges examined in this report were to be resolved. The government was, however, right to say that the digital ID should be built in-house, from the perspective of both cost and public trust. (Conclusion, Paragraph 142)
53. The announcement of the government’s final decision on digital ID should be accompanied by full costings and a full impact assessment, as well as details of controls to ensure the scheme, if it is taken forward, does not exceed its delivery timetable or agreed budget. (Recommendation, Paragraph 143)
54. If external suppliers are deemed necessary to support the development or implementation of the new digital ID, no contracts relating to the development or implementation of the new digital ID should be awarded without a competitive tender process, and all contracts should be published in full. The government should announce the decision to use external suppliers to Parliament before tendering. (Recommendation, Paragraph 144)
55. If the government decides to proceed with the new digital ID, Parliament should be given an opportunity to vote on each use case before it is added and given full access to the government’s internal impact and cost assessments to inform its decision. (Recommendation, Paragraph 145)
Formal minutes
Wednesday 20 May 2026
Members present
Dame Chi Onwurah, in the Chair
Emily Darlington
Kit Malthouse
Samantha Niblett
Lauren Sullivan
Martin Wrigley
Daniel Zeichner
Declarations of interests
The following declarations of interest relating to the inquiry were made:
Kit Malthouse declared that he was a shareholder and unpaid director of Lockhouse Systems Ltd, a software and technology development company.
Rewiring the state: Delivering digital government
Draft Report (Rewiring the state: Delivering digital government), proposed by the Chair, brought up and read.
Ordered, That the draft Report be read a second time, paragraph by paragraph.
Paragraphs 1 to 145 read and agreed to.
Summary agreed to.
Resolved, That the Report be the First Report of the Committee to the House.
Ordered, That the Chair make the Report to the House.
Ordered, That embargoed copies of the Report be made available (Standing Order No. 134).
Adjournment
Adjourned till Wednesday 3 June at 9.00 a.m.
Witnesses
The following witnesses gave evidence. Transcripts can be viewed on the inquiry publications page of the Committee’s website.
Tuesday 25 March 2025
Laura Gilbert CBE, Head of AI for Government, Ellison Institute and Visiting Professor in Practice, London School of Economics; Richard Pope, Director, Richard Pope and PartnersQ1–28
Rachel Coldicutt OBE, Executive Director, Careful Industries; Joe Hill, Policy Director, Reform think tankQ29–45
Tuesday 13 May 2025
Phil Rumens, Digital Services Manager, West Berkshire Council; Councillor Sunita Gordon, Lead Member for Resources, London Borough of SuttonQ46–69
Andrew Chevis, Chief Executive, CitizenCard; Julie Dawson, Chief Policy and Regulatory Officer, YotiQ70–93
Rt Hon Sir Iain Duncan Smith MP, Former Secretary of State, Department for Work and PensionsQ94–105
Tuesday 8 July 2025
Louis Mosley, Executive Vice President, PalantirQ106–149
Dr Vin Diwakar, National Director of Transformation (Interim), NHS England; Alex Crossley, Director of Transformation Strategy, Finance and Delivery, NHS England; Amy Freeman, Chief Digital Information Officer, University Hospitals of North Midlands NHS TrustQ150–190
Tuesday 14 October 2025
Nick Davies, Programme Director, Institute for Government; Jason Liggins, CEO, Crown Hosting Data CentresQ191–241
Gaia Marcus, Director, Ada Lovelace Institute; Jeni Tennison, Executive Director, Connected by DataQ242–269
Wednesday 19 November 2025
Rt Hon Ian Murray MP, Minister for Digital Government and Data, Department for Science, Innovation and Technology; Emily Middleton, Director General Digital Centre Design, Department for Science, Innovation and TechnologyQ270–350
Published written evidence
The following written evidence was received and can be viewed on the inquiry publications page of the Committee’s website.
DCG numbers are generated by the evidence processing system and so may not be complete.
1 Ada Lovelace InstituteDCG0018
2 AtkinsRealisDCG0022
3 Chang, Professor Kirk; and Vaduva, Dr AlinaDCG0009
4 CohereDCG0037
5 Connected Places CatapultDCG0027
6 Crown Hosting Data Centres LtdDCG0011
7 DarwinistDCG0041
8 Denezhkina, Dr ElenaDCG0028
9 Department of Science Innovation and TechnologyDCG0020
10 Durant, Mr DavidDCG0015
11 Intensive Learning Academy, Faculty of Business & Creative Industries, University of South WalesDCG0016
12 King, TimDCG0042
13 Local Government AssociationDCG0036
14 Mandal, Dr AnandadeepDCG0005
15 MedconfidentialDCG0035
16 MedConfidential)DCG0040
17 Mobile UKDCG0017
18 MozillaDCG0021
19 Open Cloud CoalitionsDCG0033
20 Policy ConnectDCG0024
21 Reform think tankDCG0013
22 Royal United Services InstituteDCG0023
23 SAS InstituteDCG0030
24 ServiceNowDCG0032
25 Smith, Dr Alan (University of Plymouth); and Dr Andy Newing (University of Leeds)DCG0012
26 Tabaghdehi, Dr S Asieh (Brunel University of London); and Professor Ashley Braganza (Brunel University of London)DCG0026
27 Taylor-Beswick, professor AmandaDCG0002
28 techUKDCG0019
29 Team Defence InformationDCG0008
30 The Centre for Digital Assets and DemocracyDCG0038
31 The Institution of Engineering and TechnologyDCG0010
32 The Open Data InstituteDCG0034
33 Thorney Isle ResearchDCG0006
34 University of BirminghamDCG0025
35 Vodafone UKDCG0007
36 Wall, Professor TonyDCG0014
37 Whippey, NicoleDCG0003
38 Wong, Dr MarkDCG0029
39 YotiDCG0039
List of Reports from the Committee during the current Parliament
All publications from the Committee are available on the publications page of the Committee’s website.
Session 2026–27
|
Number |
Title |
Reference |
|---|---|---|
|
2nd |
Pre-appointment hearing for the Chair of Ofcom |
HC 55 |
Session 2024–26
|
Number |
Title |
Reference |
|---|---|---|
|
4th |
Pre-appointment hearing for the Chair of UK Research and Innovation |
HC 1844 |
|
3rd |
Flying Blind: Innovation, Growth and the Regions |
HC 538 |
|
2nd |
Social media, misinformation and harmful algorithms |
HC 441 |
|
1st |
Pre-appointment hearing for the Executive Chair of Innovate UK |
HC 834 |
|
3rd |
Social media, misinformation and harmful algorithms: Government and Ofcom responses |
HC 1397 |
|
2nd |
Insect decline and UK food security: Government Response |
HC 717 |
|
1st |
Governance of artificial intelligence (AI): Government Response |
HC 591 |
Footnotes
1 Department for Science, Innovation and Technology, A blueprint for modern digital government, CP 1252, 21 January 2025, p. 4
2 GOV.UK, DSIT bolstered to better serve the British public through science and technology (accessed 19 May 2026)
3 GOV.UK, DSIT bolstered to better serve the British public through science and technology (accessed 19 May 2026)
4 GOV.UK, DSIT bolstered to better serve the British public through science and technology (accessed 19 May 2026)
5 Committee of Public Accounts, Forty-fifth Report of Session 2010–12, The National Programme for IT in the NHS: an update on the delivery of detailed care records systems, HC 1070
6 BBC News, Care.data: How did it go so wrong? (accessed 19 May 2026)
7 Committee of Public Accounts, Ninety-Fifth Report of Session 2017–19, Accessing public services through the Government’s Verify digital system, HC 1748
8 Business and Trade Committee, First Report of Session 2024–25, Post Office and Horizon scandal redress: Unfinished business, HC 341
9 Department for Science, Innovation and Technology, A blueprint for modern digital government, CP 1252, 21 January 2025, p. 4
10 GOV.UK, Government launches consultation on making public services quicker, easier and more secure to access with digital ID, 10 March 2026
11 Cabinet Office, Making public services work for you with your digital Identity, CP 1408, 10 March 2026, p. 16
12 Department for Science, Innovation and Technology, State of digital government review, CP 1251, 21 January 2025, p. 4
13 Department for Science, Innovation and Technology, A blueprint for modern digital government, CP 1252, 21 January 2025, p. 4
14 Department for Science, Innovation and Technology, A blueprint for modern digital government, CP 1252, 21 January 2025
15 UK Parliament, Data security across government (accessed 19 May 2026)
16 Cabinet Office, Making public services work for you with your digital Identity, CP 1408, 10 March 2026
17 Department for Science, Innovation and Technology, State of digital government review, CP 1251, 21 January 2025, p. 4
19 Department for Science, Innovation and Technology, A blueprint for modern digital government, CP 1252, 21 January 2025, p. 24
21 Department for Science, Innovation and Technology (DCG0020)
22 GOV.UK, A roadmap for modern digital government: creating a consistent approach to measuring how digital services perform (accessed 19 May 2026)
24 Department for Science, Innovation and Technology, State of digital government review, CP 1251, 21 January 2025, p. 6
25 Department for Science, Innovation and Technology, State of digital government review, CP 1251, 21 January 2025, p. 6
26 Department for Science, Innovation and Technology, State of digital government review, CP 1251, 21 January 2025, p. 6
27 Department for Science, Innovation and Technology, State of digital government review, CP 1251, 21 January 2025, p. 39
28 Department for Science, Innovation and Technology (DCG0020)
29 Department for Science, Innovation and Technology, State of digital government review, CP 1251, 21 January 2025, p. 39
32 Department for Science, Innovation and Technology, A blueprint for modern digital government, CP 1252, 21 January 2025, p. 34
33 GOV.UK, A roadmap for modern digital government: simplifying spending and approval processes to deliver new and improved services faster (accessed 19 May 2026)
35 Department for Science, Innovation and Technology, State of digital government review, CP 1251, 21 January 2025, p. 1
41 Department for Science, Innovation and Technology, State of digital government review, CP 1251, 21 January 2025, p. 7
43 Department for Science, Innovation and Technology, State of digital government review, CP 1251, 21 January 2025, p. 6
44 Department for Science, Innovation and Technology, State of digital government review, CP 1251, 21 January 2025, p. 6
45 Public Technology, EXCL: Government CDO concludes term with DSIT perm sec to oversee work of GDS and digital function (accessed 19 May 2026)
47 GOV.UK, A roadmap for modern digital government: elevate leadership, invest in talent (accessed 19 May 2026)
48 GOV.UK, A roadmap for modern digital government: elevating digital leadership across government (accessed 19 May 2026)
49 GOV.UK, A roadmap for modern digital government: elevating digital leadership across government (accessed 19 May 2026)
50 GOV.UK, A roadmap for modern digital government: elevating digital leadership across government (accessed 19 May 2026)
51 Heywood Quarterly, Delivering value through AI in central government (accessed 19 May 2026)
52 GOV.UK, A roadmap for modern digital government: building all civil servants’ digital, data and AI skills (accessed 19 May 2026)
53 Letter from the Secretary of State for Science, Innovation and Technology regarding follow-ups from 3 December 2024 session, 14 January 2025
54 Government Departments: Digital Technology, PQ 37146, 14 March 2025
55 FDA, Adopt, Innovate, Transform (accessed 13 May 2026)
56 FDA, Adopt, Innovate, Transform (accessed 13 May 2026)
57 Department for Science, Innovation and Technology, State of digital government review, CP 1251, 21 January 2025, p. 7
60 GOV.UK, A roadmap for modern digital government: getting the digital, data and AI specialists government needs (accessed 19 May 2026)
61 GOV.UK, A roadmap for modern digital government: getting the digital, data and AI specialists government needs (accessed 19 May 2026)
62 Government Departments: Digital Technology PQ 120697, 23 March 2026
63 HC Deb, 15 July 2025, col 149
64 Letter from the Chair to the Information Commissioner regarding 2022 MoD data breach, 17 July 2025 and letter from the Chair to the Chancellor of the Duchy of Lancaster and Secretary of State for Science, Innovation and Technology regarding government data handling, 24 July 2025
65 Letter from the Information Commissioner to the Chair regarding 2022 MoD data breach, 28 July 2025
66 Cabinet Office, Information Security Review 2023, 28 August 2025
67 Cabinet Office, Information Security Review 2023, 28 August 2025, pp. 15–19
68 Cabinet Office, Information Security Review 2023, 28 August 2025, p. 2
69 Oral evidence taken on 10 February 2026, Q15
70 Oral evidence taken on 10 February 2026, Q15
71 Oral evidence taken on 10 February 2026, Q18
72 Letter from the Government Chief Security Officer and Government Chief Technology Officer regarding information security standards, 20 October 2025
73 GOV.UK, Memorandum of Understanding (MOU) between the Information Commissioner’s Office and HM Government (accessed 19 May 2026)
74 Oral evidence taken on 10 February 2026, Q98
75 Letter from the Civil Service Chief Operating Officer and Permanent Secretary for the Department of Science, Innovation and Technology regarding the Government’s approach to data security, 28 August 2025
77 Oral evidence taken on 21 October 2025, Q37
78 Oral evidence taken on 10 February 2026, Q22
79 Oral evidence taken on 10 February 2026, Q29
80 Oral evidence taken on 10 February 2026, Q45
81 HC Deb, 23 April 2026, col 468
82 UK Biobank, Who we are (accessed 19 May 2026)
83 HC Deb, 23 April 2026, col 468
84 HL Deb, 28 April 2026, col 1123
85 UK Biobank, Our funding (accessed 19 May 2026)
86 Financial Times, UK Biobank says security checks not imposed because of ‘harms’ to research (accessed 19 May 2026)
87 Department for Science, Innovation and Technology, A blueprint for modern digital government, CP 1252, 21 January 2025, p. 4
88 GOV.UK, DSIT bolstered to better serve the British public through science and technology (accessed 19 May 2026)
89 Reform Think Tank (now Re:State) (DCG0013)
90 Crown Hosting Data Centres Ltd (DCG0011)
92 Department for Science, Innovation and Technology (DCG0020)
93 GOV.UK, A roadmap for modern digital government (accessed 19 May 2026)
94 Department for Science, Innovation and Technology, A blueprint for modern digital government, CP 1252, 21 January 2025, p. 31
95 Department for Science, Innovation and Technology, A blueprint for modern digital government, CP 1252, 21 January 2025, p. 17
100 GOV.UK, A roadmap for modern digital government (accessed 19 May 2026)
101 Letter from the Minister for Digital Government and Data regarding a roadmap for modern digital government, 1 April 2026
102 Department for Science, Innovation and Technology, State of digital government review, CP 1251, 21 January 2025, p. 5
103 GOV.UK, Prime Minister: I will reshape the state to deliver security for working people (accessed 19 May 2026)
106 Letter from Chair to Secretary of State for Science, Innovation and Technology regarding savings and productivity benefits from digitisation of public sector services, 28 March 2025
107 Letter from Parliamentary Under Secretary of State, Department for Science, Innovation and Technology regarding methodology behind £45bn estimate in the State of Digital Government Review, 10 April 2025
108 Letter from Parliamentary Under Secretary of State, Department for Science, Innovation and Technology regarding methodology behind £45bn estimate in the State of Digital Government Review, 10 April 2025
109 Letter from Parliamentary Under Secretary of State, Department for Science, Innovation and Technology regarding methodology behind £45bn estimate in the State of Digital Government Review, 10 April 2025
112 GOV.UK, Managing legacy technology (accessed 19 May 2026)
113 National Audit Office, Managing the risks of legacy ICT to public service delivery, September 2013
114 Committee of Public Accounts, Seventieth Report of Session 2022–23, Digital transformation in government: assessing the barriers to efficiency, HC 1229, para 18
115 Open Cloud Coalition (DCG0033)
116 National Cyber Security Centre, Annual Review 2025, 14 October 2025, p. 47
117 GOV.UK, Government Cloud First Policy (accessed 19 May 2026)
118 Department for Science, Innovation and Technology, State of digital government review, CP 1251, 21 January 2025, p. 6
119 Department for Science, Innovation and Technology, State of digital government review, CP 1251, 21 January 2025, p. 20
120 Department for Science, Innovation and Technology, State of digital government review, CP 1251, 21 January 2025, p. 9
121 Department for Science, Innovation and Technology, State of digital government review, CP 1251, 21 January 2025, p. 17
122 Department for Science, Innovation and Technology, State of digital government review, CP 1251, 21 January 2025, p. 17
123 Government Departments: ICT, HL16286, 27 April 2026
124 Crown Hosting Data Centres Ltd (DCG0011)
127 Department for Science, Innovation and Technology, State of digital government review, CP 1251, 21 January 2025, p. 8
128 Department for Science, Innovation and Technology, State of digital government review, CP 1251, 21 January 2025, p. 16
129 Department for Science, Innovation and Technology, State of digital government review, CP 1251, 21 January 2025, p. 18
131 Letter from the Permanent Secretary at the Department for Science, Innovation and Technology to the Chair of the Committee of Public Accounts regarding recommendations from the Use of AI in government report, 18 November 2025
132 Meaning up to 2028–29 for day-to-day spending and 2029–30 for investment spending
134 GOV.UK, A roadmap for modern digital government: Understanding our digital systems to improve them (accessed 19 May 2026)
135 GOV.UK, A roadmap for modern digital government: Creating common systems and platforms for all of government to use (accessed 19 May 2026)
136 Department for Science, Innovation and Technology, A blueprint for modern digital government, CP 1252, 21 January 2025, p. 15
137 The Ada Lovelace Institute, Learn fast and build things, March 2025, p. 23
138 GOV.UK, Crown Representatives and strategic suppliers (accessed 19 May 2026)
139 Business and Trade Committee, Sixteenth Report of Session 2024–26, Post Office Horizon scandal: Justice for sub-postmasters, HC 1589, para 67
140 Business and Trade Committee, Sixteenth Report of Session 2024–26, Post Office Horizon scandal: Justice for sub-postmasters, HC 1589, para 68
141 GOV.UK, CMA announces package of actions on business software and cloud services (accessed 19 May 2026)
142 Public Technology, HMRC greenlights sole bidder AWS for £500m cloud migration deal (accessed 19 May 2026)
143 GOV.UK, CMA announces package of actions on business software and cloud services (accessed 19 May 2026)
144 Competition and Markets Authority, Cloud services market investigation: summary of final decision, 31 July 2025, p. 2
145 CNBC, Palantir’s technology gives the West a critical edge in Middle East, CEO Alex Karp says (accessed 19 May 2026)
146 Wired, ICE Is Paying Palantir $30 Million to Build ‘ImmigrationOS’ Surveillance Platform (accessed 19 May 2026)
147 X (formerly Twitter), The Technological Republic in brief (accessed 19 May 2026)
148 Thiel was reported as telling the Oxford Union in January 2023, that ‘highways create traffic jams, welfare creates poverty, schools make people dumb and the NHS makes people sick’; the British public’s affection for the NHS was a case of ‘Stockholm syndrome’; and that the NHS needed ‘ripping from the ground’ and starting over, including the embrace of ‘market mechanisms’. The Guardian, Palantir’s Peter Thiel: NHS is a natural target for outspoken tech billionaire (accessed 19 May 2026)
150 X (formerly Twitter), The Technological Republic in brief (accessed 19 May 2026)
153 NHS England, NHS Federated Data Platform (accessed 19 May2026)
154 NHS England, What is the NHS Federated Data Platform? (accessed 19 May 2026)
155 GOV.UK Contracts Finder, Federated Data Platform and Associated Services (accessed 19 May 2026)
156 NHS England, What is the NHS Federated Data Platform? (accessed 19 May 2026)
157 Financial Times, NHS breaks up £400mn data contract in response to privacy concerns (accessed 19 May 2026)
160 Financial Times, NHS to grant Palantir contractors ‘unlimited access’ to patient data (accessed 19 May 2026)
161 X (formerly Twitter), post by Louis Mosley, (accessed 19 May 2026)
162 BBC News, Palantir defends its record as MPs demand more scrutiny of data use (accessed 19 May 2026)
167 The Register, Some English hospitals doubt Palantir’s utility: We’d ‘lose functionality rather than gain it’ (accessed 19 May 2026)
169 NHS England, The Single Patient Record (accessed 19 May 2026)
171 GOV.UK, The King’s Speech 2026, 13 May 2026, p. 71
172 HC Deb, 22 April 2026, col 327
173 Ministry of Defence: Palantir PQ 111951, 17 February 2026
174 Oral evidence taken on 17 March 2026, Q308
176 GOV.UK, A roadmap for modern digital government: Improving the public sector’s buying power through the Digital Commercial Centre of Excellence (accessed 19 May 2026)
177 GOV.UK, Departmental Small Business Procurement Targets (accessed 19 May 2026)
178 GOV.UK, Ministry of Defence small and medium-sized enterprise engagement (accessed 19 May 2026)
179 Andrew Holway (founder at Darwinist) (DCG0041)
180 Andrew Holway (founder at Darwinist) (DCG0041)
181 HC Deb, 22 April 2026, col 330
183 Public Technology, HMRC greenlights sole bidder AWS for £500m cloud migration deal, 24 March 2026
184 The Register, Microsoft facing multibillion legal claim over how it sells software (accessed 19 May 2026)
185 Computer Weekly, Microsoft outages: The implications of downtime on the delivery of critical public services (accessed 19 May 2026) and Government Digital Service PQ 83776, 27 October 2025
186 Open Cloud Coalition (DCG0033) and Social Market Foundation, Clearing the air: Confronting the costs to cloud adopters of restrictive software licensing practices, July 2024, p. 6
187 Open Cloud Coalition (DCG0033)
188 GOV.UK, CMA announces package of actions on business software and cloud services (accessed 19 May 2026)
189 Department for Science, Innovation and Technology, State of digital government review, CP 1251, 21 January 2025, p. 6
190 Competition and Markets Authority, Cloud Infrastructure Services: final decision report, July 2025, p. 214
191 Government Departments: Digital Technology PQ 83775, 27 October 2025
192 Government Departments: Digital Technology PQ 83775, 27 October 2025
194 GOV.UK, A roadmap for modern digital government: Improving the public sector’s buying power through the Digital Commercial Centre of Excellence (accessed 19 May 2026)
195 World Economic Forum, Why the race for tech sovereignty is a balancing act (accessed 19 May 2026)
196 Comment is Freed, Sovereignty for Sale (accessed 19 May 2026)
197 Department for Science, Innovation and Technology, State of digital government review, CP 1251, 21 January 2025 and Department for Science, Innovation and Technology, A blueprint for modern digital government, CP 1252, 21 January 2025
198 Letter from the Minister for Digital Government and Data regarding digital centre of government inquiry - follow up, 2 December 2025
199 Government Departments: ICT PQ 121743, 23 March 2026
200 Letter from the Secretary of State for Science, Innovation and Technology, 18 December 2025
201 GOV.UK, Rebuilding Britain for the new world: Liz Kendall’s speech at the Royal United Services Institute (accessed 19 May 2026)
202 HC Deb, 10 March 2026, col 103WH
203 Oral evidence taken on 3 February 2026, Q97
204 Letter from the Prime Minister to the Chair of the Liaison Committee regarding 23 March session, 13 April 2026
205 GOV.UK, Huawei to be removed from UK 5G networks by 2027 (accessed 19 May 2026)
206 House of Commons Library, Digital Sovereignty, Research Briefing 10547, 6 March 2026
207 House of Commons Library, Digital Sovereignty, Research Briefing 10547, 6 March 2026, p. 10
208 Oral evidence taken by the Liaison Committee on 23 March 2026, Q51
209 GOV.UK, AI to power national renewal as government announces billions of additional investment and new plans to boost UK businesses, jobs and innovation (accessed 19 May 2026)
210 Financial Times, Inside the German state trying to break free from Microsoft (accessed 19 May 2026)
211 Bennett School of Public Policy, Blog: what does AI sovereignty for the UK involve? (accessed 19 May 2026)
212 Computer Weekly, How to make AI work for Britain: consolidate demand, diversify supply (accessed 19 May 2026)
213 Comment is Freed, Sovereignty for Sale (accessed 19 May 2026)
214 European Parliament Committee on Industry, Research and Energy, Report on European technological sovereignty and digital infrastructure, June 2025
215 GOV.UK, New digital ID scheme to be rolled out across UK (accessed 19 May 2026)
216 GOV.UK, New digital ID scheme to be rolled out across UK (accessed 19 May 2026)
217 BBC News, Government drops plans for mandatory digital ID to work in UK (accessed 19 May 2026)
218 GOV.UK, New digital ID scheme to be rolled out across UK (accessed 19 May 2026)
219 GOV.UK, Government launches consultation on making public services quicker, easier and more secure to access with digital ID (accessed 19 May 2026)
220 GOV.UK, Government launches consultation on making public services quicker, easier and more secure to access with digital ID (accessed 19 May 2026)
221 Cabinet Office, Making public services work for you with your digital Identity, CP 1498, 10 March 2026, p. 18
225 Cabinet Office, Making public services work for you with your digital Identity, CP 1498, 10 March 2026, pp. 21–22
226 Oral evidence taken by the Home Affairs Committee on 3 March 2026, Q132
227 Home Office, 25 October 2024: Passport Transformation Programme Accounting Officer Assessment, updated 26 November 2025
228 Computer Weekly, Gov.uk One Login loses certification for digital identity trust framework (accessed 2 April 2026) and Civil Service World, One Login now in place for more than 120 government services (accessed 19 May 2026)
229 Oral evidence taken by the Home Affairs Committee on 28 January 2026, Qq. 94, 96
230 Oral evidence taken by the Home Affairs Committee on 28 January 2026, Q103
231 Oral evidence taken by the Home Affairs Committee on 28 January 2026, Q95
232 Oral evidence taken by the Home Affairs Committee on 28 January 2026, Qq. 96, 98
233 Office for Budget Responsibility, Economic and fiscal outlook, CP 1439, November 2025, p. 122
234 Oral evidence taken by the Home Affairs Committee on 3 March 2026, Q134