Artificial intelligence (AI) is becoming an important part of how we design and deliver digital services. To help product and delivery teams across the Ministry of Housing, Communities and Local Government (MHCLG) adopt AI more safely and effectively, our Technical Architecture team developed the AI Gateway – a single, shared departmental platform that gives teams a secure, consistent and faster way to access approved AI technologies.
In this blog post, I share what we did, why we did it and what we learnt.
The problem to solveProduct and delivery teams building digital services in MHCLG need to access AI capability without each needing to spend time designing how that AI access is secure and safe.
Without a central route, multiple teams would end up building separate integrations, governance approaches and support models for different AI services. Repeating this across multiple teams would have created duplication, delays and inconsistent standards.
Our team recognised early the need to focus on the wider organisational challenge affecting all digital product and delivery teams rather than a single technical requirement.
The approachOur aim was to create a capability that could be reused across the organisation, leading to cost savings, reducing time spent by each team on development and providing one well-managed and scalable solution.
It made sense to create a shared AI platform rather than a series of separate solutions for different AI providers.
Working with colleagues across the wider digital team, we led the architectural approach for the Gateway using Microsoft Azure API Management as the core platform. This gave MHCLG a single governed route to approved AI services, rather than leaving each team to design its own connection pattern.
We wanted the Gateway to be deliberately AI provider-agnostic, and to support models from multiple providers through one consistent approach that supports future integration of additional AI models.
The solutionThe solution is a reusable platform with shared controls, common onboarding and a consistent support model. It makes secure AI access available much more easily and much earlier in the development lifecycle than was previously possible through direct API access.
The Gateway is designed to support developers, data scientists, applications and services running in Azure and AWS. This allows AI to be embedded directly into departmental services, not simply accessed from individual devices.
At a departmental level, the platform provides visibility of how AI is being used, enables appropriate technical controls from the centre, tracks costs and supports cost optimisation.
A faster route to AI adoptionBy using the AI Gateway, projects can benefit from:
a standardised API for AI access clear onboarding and support processes shared security and governance controls less development effort and faster implementationThis means delivery teams can focus on solving business problems and improving services, rather than managing the underlying AI infrastructure.
Security and governance by designAs AI becomes more widely embedded into digital services, it is important to maintain the right security and governance controls.
The AI Gateway supports this by:
restricting access to approved models and vendors enforcing departmental security controls supporting audit and monitoring requirements providing central oversight of AI usage promoting compliance with departmental standardsThis creates a safer foundation for innovation and reduces the risks of ungoverned AI access.
Improved visibility and cost managementAs demand for AI grows, understanding how it is being used becomes increasingly important.
The Gateway gives teams central visibility of:
AI consumption across services usage trends and adoption patterns cost and resource useThis helps teams understand demand, manage spend and make sure AI investment delivers value.
Things we learnt that helped us design the AI Gateway Build a scalable foundationMany AI projects begin with one tool, one team or one use case. We recognised early that the solution needed to be able to scale well across a large department.
Building the Gateway on Microsoft Azure API Management and shaping it as a shared departmental platform meant the team can fully integrate with MHCLG’s existing technology stack and leverage the investment already made in this technology.
The team created a practical foundational way for MHCLG to adopt AI safely, efficiently and consistently, while still leaving room for the platform to evolve as the technology changes.
Make sure AI is used safely and appropriatelyResponsible use was built into the project from the beginning, with a clear goal of ensuring other teams could use AI safely and appropriately through this solution.
We put the solution through the departmental internal AI approval process along with special technical and data protection approvals to ensure it was assessed against internal policies. Additionally, the Gateway went through penetration testing assessment.
The platform uses existing strong authentication and RBAC access control methods alongside integration into existing monitoring, logging and auditability to provide visibility, with tooling that is backed by commercial contracts and cyber security assurance.
The project was supported by governance documentation covering acceptable use, accountability, operational responsibilities and data handling, and links into the department’s wider AI governance approach, including our AI Register and approval process.
We did not treat governance as something that slows innovation down. We showed that AI can be adopted in a way that is ambitious and practical, while maintaining the right levels of security, compliance and public trust.
Collaboration and focus on user needsOur team did not approach this work in isolation. We helped shape the architectural direction as part of a wider team effort involving colleagues across digital, Cloud, DevOps, security, governance and delivery functions.
From the outset, the Gateway was designed for shared use across all teams, not just one project or technical area. We worked with colleagues to develop reusable patterns, onboarding guidance, governance artefacts, technical documentation, support arrangements and operational processes.
The impactThe biggest impact has been making AI significantly easier, faster and more efficient for colleagues across the department to adopt responsibly.
Teams now have a clearer route to approved AI services, with common controls, onboarding guidance, monitoring and support already in place. This reduces the cost and time required to develop digital services.
The Gateway has already been adopted by multiple teams and provides access to approximately 20 AI models through a single, governed platform. Several initiatives across MHCLG are already using the platform, with more projects progressing through onboarding.
As a result, colleagues spend less time recreating technical foundations and more time exploring how AI can improve services, support users and deliver better outcomes for the public. The platform provides a strong foundation for wider AI adoption across MHCLG as demand continues to grow.
What’s nextWe continue to develop the solution to deliver lasting value to the department, based on providing consistent approaches to governance, security and support.
Our wider roadmap looks to expand the AI capabilities available through the Gateway. Future phases of work will include access to AI services hosted by additional Cloud services providers, giving teams more flexibility while maintaining the same governance, security and operational standards.
If you’re working on similar challenges across government and would like to learn more about this project, get in touch by emailing technology.team@communities.gov.uk.
seen at 14:32, 15 September in MHCLG Digital.