Who this is realistically for, and who it is not

This guide is written for a specific reader: two or three people who can build and ship a working AI system, who have some commercial delivery behind them, and who have never held a government contract. If that is you, public-sector work is now genuinely worth a look, and the reason is not sentiment. In the UK, as of September 2026, the government has launched a procurement route that pays for research and development against named challenges, lets the supplier keep the intellectual property, and, per trade-press reporting on the scheme, carries no minimum turnover requirement. That combination is unusual, and it is the first time in a while that the terms themselves — rather than the rhetoric — have favoured a small team.

It is not for everyone, and it is worth being blunt about who should close this tab. If you have never delivered a paid engagement end to end, public-sector work is the wrong place to learn; the feedback loops are long and the bid cost is real. If your evidence is entirely private — code in a closed repository, results you cannot describe, clients you cannot name — you will struggle at the assessment stage, and the fix is to build public proof first, which our guide on proof-of-work portfolios covers properly. And if your cash position cannot absorb both unpaid bid effort and a payment profile you do not control, then the honest answer is to build the buffer before you build the bid.

The rest of this piece is deliberately split into two kinds of material. The durable mechanics — how to read a lot, what counts as evidence, how consortium and subcontracting routes work, which clauses matter, how to think about cash-flow — will still be true in 2028, because they are properties of how governments buy rather than of any one scheme. The worked example is the UK's 2026 route, because it is concrete and because the terms are unusually readable. If you are in India, read the mechanics as the substance and the UK material as an illustration, then go to the India section, which is a research method rather than a scheme summary, because that is the only honest thing to give you.

What changed in public AI procurement, and why the terms matter more than the money

On 31 August 2026, at the G20 Finance Ministers and Central Bank Governors meeting in North Carolina, Chancellor John Healey MP announced a £100 million UK Sovereign AI R&D Procurement Scheme, with the first competitions now open. The framing in the announcement is worth reading closely, because the government stated directly that public procurement has not been supportive enough of smaller companies including UK startups. That is an unusual admission for a buying organisation to make about itself, and it tells you what the scheme is trying to fix. Our news write-up of the £100m scheme and what it means for startups covers the announcement in more detail.

Two terms in that scheme matter far more to a two-person team than the headline figure. The first is that upfront payments are, in the scheme's own words, "available where appropriate". The second is that "successful companies will also keep the intellectual property they create". If you have ever priced a government engagement, you will recognise both of these as the clauses that historically made public work unworkable for tiny suppliers: pay-on-delivery terms that require you to finance the entire build from your own balance sheet, and IP assignment that hands your only durable asset to the buyer. A scheme that softens both is a materially different proposition from one that simply has a large number attached to it.

On scale, and here attributing carefully to a single trade-press source: per TechMarketView, contracts under the scheme run from £250,000 to £10 million, with most anticipated in the £1 million to £3 million range, and the £100 million is spread across the scheme's lifetime running to March 2030. Read those numbers together rather than separately. A £100 million programme that runs for roughly three and a half years, at a typical contract size of £1m to £3m, is not a firehose — it is a modest number of contracts per year. That should shape your expectations and, more usefully, your targeting: you are not competing for a share of £100 million, you are competing for one specific lot against a specific, small field.

As of September 2026, bids are assessed by the Sovereign AI team, participating government departments, and independent technical experts. That assessment composition is a genuinely useful signal, and most first-time bidders miss it. A panel that includes independent technical experts alongside departmental sponsors will read your technical section properly. It means a credible evaluation methodology and a defensible architecture are worth more, relative to procurement polish, than they would be in a purely commercial assessment. A small team with strong engineering and average prose has a better chance here than the reverse.

Watch out

Bid writing is a real, unpaid cost, and for a two-person team it is the most expensive thing in this article. A serious response is days of work that you cannot invoice and cannot recover if you lose. Do not bid on a lot you cannot deliver on the assumption that you will "figure out capacity if we win" — winning a lot you cannot staff is worse than losing it, because you will then be in breach with a government buyer whose reference you were bidding to earn. If you cannot name the deliverable, name the people doing the work, and describe how you survive the payment profile, do not enter.

Read the lot before you read the money

The most common small-team mistake is to read the total scheme value, get excited, and then try to reverse-engineer a bid that justifies a large number. The discipline that actually wins is the opposite: ignore the money entirely on the first pass, read the challenge statement, and ask one question — what is the smallest complete deliverable inside this challenge that two people could own end to end and hand over with a straight face? Everything else in the bid follows from your answer, including the price.

"Complete" is the load-bearing word. Public buyers are wary of partial work that leaves them with an integration problem, so a deliverable that stops halfway is worth less to them than a smaller one that finishes. A reproducible evaluation harness for a specific task, delivered with its dataset, scoring methodology and documentation, is complete. "Improve model performance" is not. A hardened reference implementation of one workflow, with a threat model and a test suite, is complete. "AI transformation" is not a deliverable, it is a category.

The four 2026 UK challenges, decomposed

As of September 2026, the scheme's four initial challenges and their sponsoring departments are set out below, along with the shape of deliverable a small team could plausibly own and the thing that most reliably disqualifies one. The decomposition column is my read, not scheme text; treat it as a worked example of the method rather than as guidance from the buyer.

Challenge (as of September 2026) Sponsoring department Deliverable shape a small team can own What disqualifies a two-person bid
NHS productivity Department of Health and Social Care One narrow clinical or administrative workflow, evaluated against a documented baseline, with an information-governance model written down Assuming you can touch patient data on your own terms; ignoring information-governance lead times, which are material and must be planned for
Driving compute efficiency Department for Business, Innovation, Science and Trade A measured optimisation on a defined workload — inference cost per unit of output, or throughput per watt — with a reproducible benchmark harness Benchmark claims you cannot reproduce on the buyer's hardware; no methodology section; efficiency gains measured only on your own convenient workload
Integrating AI at pace across Defence mission environments Ministry of Defence A bounded integration or evaluation component within a larger prime-led programme, delivered as a named subcontractor No cleared personnel and no plan to get there; clearance is a material lead time, not a formality, and a two-person team rarely wins this lot directly
Agent security and resilience testing National Cyber Security Centre A red-team methodology or test suite for a specific agent failure class, with reproducible cases and a written threat model Security work with no threat model; a tool with no methodology behind it; findings that cannot be independently re-run

Look at the pattern across those four rows, because the pattern is the transferable lesson. In every case the small-team-winnable version is narrow, measurable and reproducible, and in every case the disqualifier is a claim the buyer cannot verify or a lead time the bidder did not plan for. That holds for a state government tender in India as much as it does for a Ministry of Defence lot in the UK. Narrow and verifiable beats broad and impressive, consistently, because the assessor's job is to reduce risk rather than to be excited.

How to re-check the list, because it will change

Say this plainly: the four challenges above are the initial challenges as of September 2026, and both the challenge list and the lot values will change over the scheme's lifetime to March 2030. Anything you read in a guide like this one — including this one — decays. So build the habit of checking primary sources rather than summaries. The scheme's own material sits on gov.uk, and the wider sovereign AI programme has its own site at sovereignai.gov.uk. Before you commit bid effort, confirm three things directly from the buyer's own pages: which challenges are open on the date you are reading this, what the contract value range is at that point, and what the assessment criteria and submission deadline actually say. If a summary and a primary source disagree, the primary source wins, and if the primary source is silent, treat the detail as unknown rather than as reported.

The evidence pack: what "prior delivery" means when you have none

Every public-sector bid asks a version of the same question: have you done this before, and can someone check? For a small team with no government track record, this is the section where bids quietly die, and it is also the section where the most improvement is available, because the fix is entirely within your control and can be built once and reused.

The mental shift is this. A large supplier answers "have you done this before" with institutional references — named contracts, named departments, someone the assessor can ring. You cannot do that, so stop trying to imitate it. What you can do is offer something a large supplier usually cannot: evidence the assessor can verify themselves, immediately, without making a phone call. A reproducible eval harness, a published methodology, a threat model, a demo with a fixed scope and a fixed seed. Reproducibility is a small team's structural advantage in a technically-assessed competition, and the panel composition described above — departments plus independent technical experts — is precisely the audience that rewards it.

What the bid is really asking The artefact that satisfies it How the assessor verifies it
Have you delivered comparable work? Two or three delivery notes: problem, constraint, what shipped, what was measured, what you would do differently Reads as an engineer's account, not marketing; specifics and trade-offs are named
Can you measure whether it worked? An evaluation suite with a documented dataset, scoring rubric and baseline Re-runs it, or reads the rubric and checks it measures the stated outcome
Do you understand where data sits? A reference architecture diagram with trust boundaries, data residency and access paths marked Traces one data item end to end and sees who can reach it
Have you thought about how it fails? A written threat model plus a failure-mode register with mitigations Checks whether the obvious attack or failure is listed and answered
Does the thing actually exist? A reproducible demo: pinned versions, fixed seed, declared scope, honest limitations Runs it and gets the documented result
Who exactly are these two people? A public, verifiable builder profile per named team member, linking to shipped work Opens the link and confirms the humans and the history are real

That last row is worth dwelling on, because it is the row small teams treat as an afterthought and assessors treat as a sanity check. When a bid is submitted by a company nobody in the room has heard of, the first thing an assessor does is look up the people. If what they find is a bare company registration and a landing page with stock photography, the bid starts from suspicion. If what they find is a durable, public profile for each named delivery lead — role, location, verifiable shipped projects, work history — the bid starts from a baseline of credibility that you did not have to argue for in prose. This is exactly the job a Verified Builder profile does: it is a linkable evidence surface that outlives any single bid, sits under a domain you do not have to maintain, and answers "are these people real and have they shipped" in one click. Put the link in the team section of every response you write.

Building that evidence in the open compounds faster than building it privately, for the same reason it works in consulting: the artefacts accumulate an audience of exactly the people who might buy. Our guide on building in public as an AI engineer covers the mechanics. For public-sector work specifically, the useful discipline is to publish the methodology rather than the client detail — the eval design, the threat model shape, the architecture pattern — so that you build a citable body of work without ever putting a client's confidential material in public.

Here is a manifest structure worth keeping in your repository and updating after every engagement. The point is not the file format; it is that the evidence pack becomes a maintained asset rather than something you scramble to assemble in the last forty-eight hours before a deadline.

evidence_pack:
  version: 2026-09
  team:
    - name: "Delivery lead"
      profile_url: "https://aitechconnect.in/p/?h=your-handle"
      security_status: "none | in progress | held"
      committed_days_per_week: 3
    - name: "Second engineer"
      profile_url: "https://aitechconnect.in/p/?h=other-handle"
      security_status: "none"
      committed_days_per_week: 2

  delivery_notes:                   # 2-3 max, one page each
    - title: "Retrieval over regulated document set"
      sector: "financial services"
      constraint: "no data leaves tenant"
      shipped: "eval harness + retrieval service"
      measured: "answer accuracy vs documented baseline"
      reference_available: true
      redacted: true                # client named only under NDA

  evaluation:
    suite_url: "public repo or on-request bundle"
    dataset: "described; provenance stated; licence noted"
    rubric: "scoring criteria written down"
    baseline: "what you compared against, and why"
    reproducible: true              # pinned deps, fixed seed

  architecture:
    diagram: "reference-architecture.pdf"
    trust_boundaries: marked
    data_residency: "stated per component"
    third_party_models: "listed with hosting location"

  security:
    threat_model: "threat-model.md"
    failure_register: "failure-modes.md"
    certifications: "list what you hold; do not imply what you do not"
    subprocessors: "named, with location"

  commercial:
    payment_profile_tolerance: "weeks of runway without receipt"
    insurance: "types and limits held"
    advisers: "procurement lawyer, accountant — named, engaged"
Pro tip

Build the reusable ninety per cent of a bid once, before a live competition, and keep it current. Your architecture pattern, security model, eval methodology and team evidence do not change per lot — only the challenge-specific sections do. Teams that maintain a standing evidence pack write a serious response in two days; teams that start from nothing take two weeks and submit something thinner. The pack is also the thing that lets you say no cheaply, because you can tell within an hour of reading a lot whether your existing evidence maps to it.

The three things that kill small-team bids

Across public buying in both markets, small-supplier bids fail for three reasons far more often than for any technical shortcoming. None of them is about whether you can build the thing. All three have mitigations, and all three have to be addressed in the bid document rather than hoped past.

Delivery capacity

An assessor's first instinct on reading a two-person bid is "what happens when one of them is ill?" It is a fair question and you must answer it explicitly, because if you do not, the assessor will answer it themselves and their answer will be worse than yours. Do not inflate the team; that is transparent and it costs you credibility. Instead, be specific about committed capacity in days per week per named person, state which parts are on the critical path, and name your escalation route — a subcontractor, a specialist associate, a partner firm — with evidence that the relationship actually exists rather than being aspirational.

The stronger structural mitigation is to stop bidding alone. Two routes matter. A consortium bid puts you alongside complementary small suppliers with one named lead who carries the contractual relationship; you own a defined workstream and the consortium collectively answers the capacity question. Subcontracting to a prime is often the better first move: you are a named specialist inside someone else's bid, the prime carries the procurement machinery and the balance-sheet risk, and you get a delivered public-sector engagement on your record without having to be the entity that survives the payment terms. A first engagement as a named subcontractor is a legitimate and underused way in, and it converts into direct bidding later far more reliably than a heroic solo attempt that fails at assessment.

Security posture

Security is where small teams most often discover a lead time they did not budget for, and the honest framing is that these are material, plan-for-them delays rather than administrative formalities. Personnel clearance for defence-adjacent work takes time that you cannot compress by wanting it more. Information-governance approval for health data is a substantive process with its own timetable. I am deliberately not giving you numbers for either, because they vary and because a stale figure in your plan is worse than an acknowledged unknown. What you can do — and what strong bids do — is state clearly what you hold today, what you have started, what the dependency is, and how the delivery plan accommodates it. An assessor reading "we hold none of this and here is our sequenced plan with the dependency named" is reassured. An assessor reading a plan that silently assumes instant access is not.

The same discipline applies to your architecture. Public buyers in regulated environments care enormously about where data goes, and a bid that cannot answer that precisely will not progress regardless of model quality. Know your data residency per component, name your subprocessors and their locations, and be able to describe the deployment shape that keeps sensitive data inside the buyer's boundary. If your capability only works by sending data to a third-party API in another jurisdiction, say so up front and price the alternative; our guide on air-gapped LLM deployment for banks, insurers and the NHS covers the patterns that survive that constraint.

Cash-flow

This is the failure mode that kills teams after they win rather than before, and it is the one small suppliers consistently underestimate. Public payment cycles are not startup payment cycles. A contract in the £1m to £3m range, per TechMarketView's read of the 2026 UK scheme, is life-changing revenue for a two-person team and also a serious working-capital problem if the money arrives behind the work. You have to model the cash profile before you price, not after you win.

Three mitigations are worth building into the bid itself. First, ask about upfront payment where the scheme allows it — the 2026 UK scheme states that upfront payments are "available where appropriate", and a bidder who does not raise it will not receive it. Second, propose staged milestones with payment attached to each, sized so that no single unpaid stretch exceeds your runway; a milestone structure is also a risk-reduction feature from the buyer's perspective, so proposing one strengthens rather than weakens your bid. Third, know your runway in weeks and let that number veto lots you cannot survive. If the honest answer is that you cannot finance the shape of the work, the correct decision is not to bid, and there is nothing shameful in it.

Avoid

"Our platform leverages state-of-the-art AI to transform departmental productivity, delivering step-change improvements across the organisation's data estate." This says nothing an assessor can check, names no deliverable, and reads as though it could have been submitted for any of the four challenges. A technically-literate panel discounts it immediately.

Recommended

"We will deliver a reproducible evaluation harness for one named workflow, including a 400-case dataset with stated provenance, a published scoring rubric, and a documented baseline. Success is defined as the harness re-running to the same result on the department's own infrastructure, operated by departmental staff, without our involvement. Two named engineers, three days a week each, across four milestones with payment on acceptance of each." Same underlying capability as the paragraph above; entirely different bid, because every claim is checkable and the handover is the deliverable.

That contrast is the single highest-leverage edit you can make to a draft response. Go through your document and, for every sentence, ask what an assessor would have to do to verify it. If the answer is "take our word for it", rewrite the sentence to name a deliverable, a measurement or an artefact. If the answer is "run the thing", you are writing a strong bid.

It also helps to write the response in a fixed skeleton so that you are never staring at a blank page under deadline. The structure below is not a scheme template — always follow the buyer's own required format — but as a drafting scaffold it forces every one of the three failure modes to be answered on the page rather than in your head.

1. THE DELIVERABLE                                   [~200 words]
   One paragraph. What exists at the end, who operates it,
   and how the buyer knows it works. No adjectives.

2. WHY THIS DELIVERABLE ADDRESSES THE CHALLENGE      [~250 words]
   Quote the challenge statement. Map your deliverable to it.
   State explicitly what you are NOT doing.

3. METHOD AND ARCHITECTURE                           [~500 words]
   Reference architecture. Trust boundaries. Data residency.
   Evaluation design: dataset, rubric, baseline, reproducibility.
   Named third-party dependencies and where they run.

4. TEAM AND CAPACITY                                 [~300 words]
   Named people. Days per week each. Critical path owner.
   Link each person's public profile.
   Escalation route: named subcontractor or associate, relationship evidenced.

5. EVIDENCE OF PRIOR DELIVERY                        [~350 words]
   2-3 delivery notes. Problem, constraint, shipped, measured.
   What is reproducible today, and how the assessor can check it.

6. SECURITY AND ASSURANCE                            [~300 words]
   Held today / in progress / not held, stated plainly.
   Lead-time dependencies named and sequenced in the plan.
   Threat model and failure register referenced.

7. MILESTONES, PRICE AND PAYMENT PROFILE             [~250 words]
   Milestones with acceptance criteria and payment on each.
   Upfront payment request, where the scheme permits it.
   Assumptions and dependencies on the buyer, listed.

8. RISKS AND WHAT WOULD MAKE US STOP                 [~200 words]
   Top three risks, owner and mitigation each.
   The condition under which you would recommend halting.
   This paragraph builds more trust than any other.

Every article here is written by a Verified Builder. Want your name on the next one?

Section four of that skeleton asks you to link a public profile for each named engineer. A Verified Builder profile is that link: a durable, verifiable page that ties your shipped projects and work history to a real human, ready to drop into a bid, a capability statement or a consortium introduction. AI Tech Connect lists AI engineers, founders and researchers across India and the UK, and it is free to join — early profiles get the Founding Builder badge while spots last.

Become a Verified Builder →

IP, data and liability: read these clauses line by line

Before the caveat, the caveat: nothing here is legal advice, and the sensible pattern for a small team is to budget a few hours of a procurement lawyer's time for your first public-sector contract and to treat that as a cost of entry rather than an optional extra. What follows is a list of things to get advice on, and the questions to walk in with.

Intellectual property first, because it is the clause that determines whether the engagement builds your company or merely pays it. The 2026 UK scheme's position is stated plainly: "Successful companies will also keep the intellectual property they create." That is favourable and it is also not the end of the analysis. Ask what licence the buyer receives in what you create, how broad it is, whether it extends to other departments, and whether it is perpetual. Ask how background IP — everything you brought with you — is defined and protected, because a loose definition can pull your existing codebase into the scope of the contract. Ask what happens to jointly-created material, and what your rights are to reuse the work with a different client. A supplier-favourable headline with a very broad buyer licence underneath is a different deal from what it appears to be.

Data terms next, and here the questions are more concrete. Establish who the controller is and who the processor is for every dataset in the engagement, because that determines who carries which obligations. Establish whether you may use the buyer's data to improve your own models — the default answer is usually no, and you should design as though it is no. Establish the residency requirement per dataset, the retention and deletion obligations at the end of the contract, the audit rights the buyer holds over you, and what you must do in a breach and within what window. For health and defence-adjacent work, expect these to be substantially stricter, and expect the approval process itself to be a material lead time in your plan.

Liability last, and this is where a two-person balance sheet meets an institutional risk appetite. Look for the liability cap and what it is a multiple of. Look for the carve-outs that sit outside the cap, because those are the ones that can exceed your company's entire value. Look at the indemnities you are being asked to give and read them against what your insurance actually covers. Look at the insurance types and limits the contract requires, and price them into your bid rather than discovering them after award. And look at the termination provisions: how the buyer can exit, on what notice, and what you are paid for work in progress. The point of reading all of this before you write is that most of it is priceable — you can absorb a term, or price it, or negotiate it, or decline the lot — but only if you read it early enough for those options to still exist.

Finding the Indian equivalent: a research method, not a scheme summary

If you are building in Bengaluru, Hyderabad, Pune or Chennai, the mechanics in this article transfer directly — narrow deliverable, verifiable evidence, honest capacity, priced terms — but the routes are different, and I am not going to give you thresholds, deadlines or portal specifics for Indian public AI procurement, because I do not have sourced facts for them and a confidently wrong number would cost you real bid days. What I can give you is the method for finding and reading the equivalent route yourself, which is more durable anyway.

Start from two names, both of which are real and both of which are starting points rather than answers. The IndiaAI Mission is the national programme umbrella under which AI-specific initiatives, calls and pillars are organised, and it is where you look for AI-specific opportunity announcements and the sponsoring bodies attached to them. The Government e-Marketplace is the central procurement platform through which a very large share of Indian public buying flows, and it is where general goods-and-services procurement, including much technology buying, is actually listed and transacted. Between them they cover both halves of the question: where AI-specific programmes are announced, and where routine public buying happens.

From those two starting points, run the following as a research task rather than a reading task. First, identify the sponsoring body for your capability — a central ministry, a state department, a public sector undertaking, a public hospital network — and find its own tenders, notices and expression-of-interest pages, because the primary document always lives with the buyer rather than with the aggregator. Second, register on the procurement platform as a seller, because until you are registered you cannot see everything, cannot receive notifications and cannot respond; do this before you need it, since registration itself takes time. Third, read the full documents for two or three tenders that have already closed in your category, and read them slowly: eligibility conditions, technical qualification criteria, the evaluation split between technical and financial scores, the payment schedule, the security deposit or performance guarantee requirement, and the IP and data clauses. Closed tenders are free education and nobody uses them.

Then verify before you commit. For any live opportunity, check every threshold and date against the primary tender document rather than a summary, a news article or a guide like this one, and note that these vary by buyer and change between rounds. Confirm whether prior-experience or turnover conditions apply to your specific category, whether any small-enterprise registration route changes them, what the bid security requirement is in cash terms, and whether consortium or joint-bidding is permitted and on what conditions. Where the document is silent or ambiguous, use the clarification window — asking a written question during the official query period is normal, expected, and one of the most underused tools available to a small bidder.

Finally, ask people who have done it. A single half-hour conversation with someone who has delivered a public contract in your category will teach you more about the real payment behaviour, the approval sequence and the documentation burden than any amount of desk research. This is one of the most direct returns on being visible and connected in the builder community, and it is the same muscle that wins commercial work — our guide on landing your first AI consulting clients covers how to build that network deliberately rather than hoping for it.

A realistic first 30 days, whether or not you bid

Everything above is useless as reading and useful as a sequence. Here is a thirty-day plan that leaves you better off even if you decide not to bid on anything, because the outputs are reusable assets rather than a single submission.

  • Days 1–3 — Decide honestly. Write down your runway in weeks, your committed days per week per person, and what security clearances or data approvals you hold today. If any of those numbers rules you out of the lots available, you have saved yourself two weeks of unpaid work. That is a good outcome, not a failure.
  • Days 3–7 — Read primary sources. Go to the buyer's own pages for your market — gov.uk and sovereignai.gov.uk in the UK, the IndiaAI Mission and the Government e-Marketplace as starting points in India — and confirm what is actually open, at what values, on what criteria, with what deadline. Do not rely on any summary, including this one.
  • Days 5–12 — Build the evidence pack. Assemble the manifest above: two or three delivery notes, one eval suite with a documented rubric and baseline, one reference architecture with trust boundaries marked, one threat model, one reproducible demo. This is the asset that makes every future bid a two-day job.
  • Days 10–18 — Find your route in. Identify three primes or larger suppliers already delivering in your challenge area and open a conversation about being a named specialist subcontractor. Identify two complementary small suppliers you could consortium with. Both routes are faster than bidding alone.
  • Days 18–25 — Read the terms and get advice. Pull the contract terms for a live or recently closed opportunity and read the IP, data and liability clauses properly. Budget a few hours of a procurement lawyer's time. Decide what you can absorb, what you must price, and what would make you decline.
  • Days 25–30 — Write, or decide not to. If a lot clears all your filters, draft it against the skeleton above and submit. If none does, write down exactly which filter failed and what would have to change. That note is your targeting brief for the next round.

The reason this plan is worth running even if you never submit a bid is that five of the six outputs are reusable. An honest capacity and runway model tells you which commercial work to take as well as which lots to enter. An eval suite and a reference architecture are assets you can show any buyer, public or private. A verifiable team page pays off on every inbound enquiry. A relationship with a prime is a business-development channel that persists. Public-sector bidding, done properly, is mostly an exercise in becoming the kind of supplier that is easy to buy from, and that pays regardless of who is buying.

Where public work sits alongside everything else you could do

One last piece of framing, because a procurement contract is only one of several ways to get paid for the same capability, and the right choice depends on what you want to give up. The table below sets the three main routes side by side. Note the first two rows are the two distinct UK instruments discussed above: the £100 million procurement scheme buys your output, while the separate £500 million UK Sovereign AI Fund — an equity instrument investing from pre-seed to growth with cheques of £1m to £10m across compute, foundation models, health and life sciences, scientific discovery, and trust and safety, alongside sovereign compute of up to one million GPU hours, visa support and strategic assets worth up to £10m — buys a share of your company. They are not alternatives to each other in any simple sense, and they are certainly not the same thing.

Route What you give up Cash profile Who it suits
Public procurement contract (e.g. the UK £100m R&D scheme) Time and scope control; unpaid bid effort; compliance overhead. Under the 2026 UK scheme, not your IP — successful companies keep what they create Lumpy and milestone-driven; upfront payment available where appropriate under the 2026 UK scheme; you must finance the gaps Teams with a narrow, verifiable deliverable and enough runway to absorb an institutional payment cycle
Equity investment (e.g. the separate UK £500m Sovereign AI Fund) Ownership and a degree of control; you take on growth expectations and governance A single large injection up front; no delivery-linked receipts Teams building a product company in one of the fund's priority sectors, not a services practice
Private-sector consulting retainer No ownership of the resulting IP; and a lower ceiling with no institutional reference Predictable monthly revenue; short payment cycles; easy to model Almost every small team as its base load, including while bidding for public work

For most two-person teams the correct answer is a retainer base plus selective public bidding, not one or the other. The retainer pays the rent and funds the unpaid bid days; the public contract, when it lands, buys you a reference that changes what you can charge everywhere else. If you are building that base load, our guides on scoping a two-week paid pilot and on writing the internal business case that unlocks budget and headcount are the two most directly useful, because a public-sector bid is essentially an internal business case written for a buyer who has to justify it upward. The disciplines are the same: name the outcome, show the evidence, price the risk.

And keep an eye on the wider market conditions, because they change what a public reference is worth. UK AI funding has been running at record value on a flat deal count, as we covered in our analysis of the record-value, flat-count pattern — bigger cheques into fewer companies, which makes differentiation matter more for everyone outside the top tier. A delivered government contract is one of the few credentials that differentiates a small team without requiring capital, which is precisely why the bid effort can be worth it despite the cost.