Last Updated on August 27, 2026 by Karl Thompson
Every working day, around 25,000 letters arrive at the Department for Work and Pensions and are read by a model before they are read by a person.
The department calls them whitemail: physical post for which there are no automatic handling rules — loosely, everything that is not a DWP-issued form. Letters that arrive without a reference number, written by people who could not find the right form or did not know there was one. Two tools process them. One classifies each letter into one of nine themes so it can be routed to the right benefit line. The other reads the content and context to identify a writer who may be vulnerable, and assigns a reason from the department’s prescribed list: financial hardship, domestic violence and abuse, drugs and alcohol, mental health, suicide and self-harm.
The output is a daily list of case references with no personal details attached, passed to an analytics team, who pass it to the teams that provide specialist support. A person decides whether to intervene. The model does not decide anything.
None of this is secret. It has a published transparency record on GOV.UK running to several thousand words, which is more than can be said for most such tools anywhere in the world. The record names the model — BART, a zero-shot classifier originally released by Facebook AI — names the contractor, Accenture, describes the procurement as an open competition against a framework call-off, lists the impact assessments completed, and states that the system runs on Amazon Web Services with no connection to the internet.
Whether it is a good idea is a separate question, and the honest answer is that it probably is. A letter from someone in crisis that sits unread for three weeks is a worse outcome than a letter read by a machine on the day it arrives.
The question this article is about is a different one. Not whether these systems work. Whether there was ever a moment at which anyone could have said no.

This article is part of a series on the systems that organise everyday life and are difficult to see from inside them. The series hub sets out the argument and lists the other articles.
What Does It Mean to Call AI “Infrastructure”?
Infrastructure is the stuff other things run on. It is defined less by what it is made of than by its position: many activities depend on it, they cannot easily substitute for it, and the dependency accumulates until removing it would be a crisis rather than an inconvenience.
By that definition AI is becoming infrastructure at two levels at once, and they look nothing alike.
The first is physical, and it resembles every other infrastructure buildout in history. Compute has to sit somewhere, drawing power. The government’s stated commitment is to raise national AI compute capacity from 2 exaFLOPs in 2024 to 420 by 2030, of which the first tenfold step — to 21 exaFLOPs — is reported as achieved. Five AI Growth Zones have been designated: sites with planning support and access to substantial power, intended to get data centres built faster than the ordinary process allows. The government reports £68 billion of investment pledged since January 2025.
The second level is the one people actually meet, and it does not look like a buildout at all. It looks like a slightly better sorting office. One third of chest X-rays in the NHS are now processed with AI assistance. A tool reads planning documents and extracts the key information in around two minutes. And 25,000 letters a day are read for signs that the person who wrote them is in trouble.
The second level is where the dependency forms. A supercomputer is a capital asset. A triage system that has run for two years, around which staffing has been arranged and a backlog target set, is something else. It is load-bearing. You cannot switch it off on a Tuesday to see how things go.
Why Is This Sequence Different?
Every infrastructure is adopted before it is governed. Railways ran for decades before accidents produced railway law. Electricity was wired into houses before anyone standardised the voltage. Nobody consented to the telephone network; it arrived, then it was everywhere, then it was regulated.
So the pattern is not new. What is new is the interval.
The lag between adoption and governance was historically set by how long the thing took to build. Track had to be laid, cables run, pipes dug. That physical slowness gave societies a decade or two in which the dependency was growing but not yet total — time in which people noticed, objected, litigated and eventually legislated. The gap was not designed. It was a side effect of construction being hard.
Software has no such lag. A department can procure a tool, deploy it across a service and reorganise a workflow around it inside a financial year. And where previous infrastructures spread despite the state, this one is being spread deliberately by it: the explicit aim of policy is to accelerate adoption across public services and scale proven tools nationally. Speed is not an accident here. It is the objective.
Which produces an unusual situation. The dependency is forming faster than the description of it.
Can Anyone List the AI Systems Already in Use?
Not yet, and the attempt is instructive.
Britain has one of the world’s first mechanisms for this: the Algorithmic Transparency Recording Standard, published in November 2021, which gives public bodies a template for describing an algorithmic tool — what it does, what data it used, how it affects decisions — and a public repository to publish it in. It is genuinely ahead of most of the world.
Use of the standard became mandatory across central government in 2024, rolled out in phases from March. Each organisation was asked to map all the algorithmic tools it operates that fall within scope — tools that either significantly influence a decision with a public effect, or interact directly with the public — and publish a record for each.
The result, stated by the team responsible: 53 new records over the following twelve months, bringing the total to 59 by May 2025.
Fifty-nine, across every central government department and the arm’s-length bodies running frontline services.
The interesting thing about that number is not that it seems small. It is that there is no way to know whether it is small. No independent count exists of how many in-scope tools are running, against which the published records could be measured, because establishing that count is the exercise. Departments were asked to map their own tools and publish what they found. The inventory and the compliance are the same activity, which means the only available measure of how complete it is comes from the organisations doing it.
This is not a scandal and should not be written as one. The direction of travel is right, the numbers are rising, the standard has been revised in response to what its users found difficult, and the intention is to extend it further. Compared with almost any other country, Britain is doing this well.
But it establishes the shape of the thing. A tool is built or procured. It is deployed. It changes how a service runs. And then, afterwards, it is written down. The whitemail record was published on 27 November 2025, describing a system already in production. The record follows the deployment, and it follows the deployment because there is no mechanism that could make it precede one. There is no equivalent of planning permission for an algorithm — no point at which a public body must ask before it may, rather than describe after it has.
Who Loses When Dependency Forms Faster Than the Rules?
The people who are read before they are told.
That is the named group and it is a specific one: everybody who writes to the DWP without a case reference. Around 25,000 of them a day, by the department’s own count. They are, definitionally, people who could not use the standard route — the letter was the workaround. Their correspondence is converted to machine-readable text, including handwriting, and assessed against a list of vulnerability themes.
The cost cannot be given as a number, and it is worth saying why rather than reaching for a proxy. What these people lose is not money, and in most cases not a worse outcome — being flagged probably helps them, and the department’s own account is that this is an additional service rather than a replacement for anything.
What they lose is the position from which a person could decline. And the transparency record is unusually clear about the shape of that absence. Under the heading for appeals and review, it says: not applicable, because the output does not positively or negatively affect the award of a benefit or the size of a payment.
That is true, and it is also the whole point. The tool does not decide entitlement. What it does is determine whether a letter from someone describing financial hardship or self-harm moves up a queue. That is consequential without being a decision, and because it is not a decision, none of the machinery that attaches to decisions attaches to it. No appeal, because there is nothing classed as appealable. No consultation, because nothing was decided.
There is a second, sharper version of the same cost, and it applies to a group that cannot be counted at all: people affected by in-scope tools whose records have not yet been published. That group exists — more records are added each month, which means more tools are running than are described. How many people it contains is not something I can tell you. That is not a gap in the research. It is the finding.
The mechanism of transfer is procurement, and the record names it precisely: an open competition against a framework call-off, with a contractor supplying most of the developers. That is an ordinary operational purchase, of a kind departments make constantly and are not required to consult on. The decision the public has an interest in — whether people’s letters should be machine-read — is not a decision anyone takes as such. It is the aggregate of many purchasing decisions, each unremarkable, none of them the moment at which the question was put.
Who avoided the cost? Not the officials, who are working on real backlogs with real constraints, and who in this instance documented their work more thoroughly than they were obliged to. The avoided cost is temporal rather than distributional. The consultation that would have preceded a comparable change to a physical service was not skipped by anybody. It was never triggered, because nothing in the process treats a software purchase as the kind of change that triggers it.
A second group, briefly, because it belongs elsewhere and I will not develop it: public bodies themselves. The whitemail system runs on Amazon Web Services, which places it inside the same tenancy relationship as the rest of the public sector’s digital estate — with the difference that a triage model, once workflows have been rebuilt around it, is harder to move than a file store.
The Interval That Used to Exist
There is a comforting version of this argument that says societies always catch up, and history is behind it. The factory acts came. The railway inspectorate came. Electrical standards, telephone regulation, road traffic law — all late, all eventually.
The difficulty is that the catching-up was never a property of societies. It was a property of the gap. Infrastructure took years to install, and in those years the objections found their voice, the harms became legible, and the institutions that would govern the thing worked out what they were governing. The lag looked like deliberation. It was mostly construction time.
Remove the construction time and deliberation does not speed up to match. It is made of the same slow materials it always was: cases, complaints, inquiries, select committees, statutes. What changes is only how much has been built before any of that begins. A dependency that takes eighteen months to become load-bearing will be load-bearing long before the first serious argument about it concludes.
Which is why the transparency records matter more than they look. They are not a regulation and they restrain nothing. They are the beginning of a description — the point at which a society can at least say what it has installed. The striking thing about the AI buildout is not that it is happening without rules. It is that it is happening without an inventory, and an inventory is what every previous infrastructure had by the time anyone needed to argue about it.
The whitemail record is a good document. It names the model, the contractor, the procurement route, the risks considered and the assessments completed. Read it and you know what the department has built. What it cannot tell you, because no document can, is who agreed to it — and the answer is that the question was never in a form anyone could answer. You cannot contest the terms of a dependency you have not finished counting.
More in this series
Previously: Semiconductors: The Cheapest Part of the Chain Is the One That Stops It — how a global division of labour gave the most leverage to the stage that earns the least.
Next: The Decision Nobody Made — what nine systems turn out to have in common. (Not yet published. Point at the hub until it goes live.)
All articles in this series: How Modern Society Works.
References
Government transparency records
Department for Work and Pensions, Whitemail Insights and Vulnerability Scanner, Algorithmic Transparency Record, published 27 November 2025. The volume of letters processed, the definition of whitemail, the two tools and their outputs, the vulnerability themes, the BART model, Accenture’s role and the procurement route, the human review process, the absence of an appeals mechanism, the AWS hosting, and the impact assessments completed.
Government departments and digital service
Government Digital Service, Making the Algorithmic Transparency Recording Standard mandatory across government, 8 May 2025. The standard’s 2021 origin, the 2024 mandate and its phased rollout, the definition of an in-scope tool, and the count of published records.
Department for Science, Innovation and Technology, AI Opportunities Action Plan progress. Compute capacity figures, AI Growth Zones, investment pledged, and the public service deployment examples.